Are Claude skills safe? How to check one before you install it
Agent skills can run scripts and read your files. Here's what a skill actually is, what can go wrong, and a five-minute checklist before you install one.
Oct 4, 2026 · 6 min read
Skills are one of the most useful ways to extend AI agents like Claude, Codex and Cursor. They're also a new way to get something onto your computer that you didn't fully read. This guide explains what a skill is, what the real risks are, and how to check one in a few minutes.
What is a skill?
A skill is a folder. At minimum it contains a file called SKILL.md: a short description at the top (the "frontmatter") followed by instructions written in plain language. Many skills also include scripts, templates or reference files the agent can use.
The agent reads the short description of every installed skill. When your request matches one, it loads the full instructions and follows them, which can include running the bundled scripts. That's what makes skills powerful: they turn a general assistant into one that knows exactly how to, say, fill in a PDF form or follow your brand guidelines.
Why that matters for safety
When you install a skill, you're giving a stranger's instructions to an assistant that can often read your files, run commands and reach the internet. Most skills are written in good faith. But the same capabilities that make a good skill useful make a malicious one dangerous. The main risks:
- Prompt injection. Instructions hidden in the skill tell the AI to do something you never asked for, like quietly uploading a file, and to not mention it. Read our plain-English guide to prompt injection.
- Hidden text. Invisible Unicode characters can hide instructions from a human reading the file while the model still sees them.
- Risky scripts. A bundled script might read your SSH keys or
.envfiles, send data to a remote server, or download and run more code. - Persistence. A script could edit your shell profile, add a scheduled task, or change your agent's settings so the effects outlast the session.
- Updates. A skill that was fine when you checked it can change later if you install straight from someone else's repository.
A five-minute checklist
- Know the source. Who published it? Is the repository active, and do other people use it? Official skill repositories from the vendor are a safer starting point than a random fork.
- Read SKILL.md top to bottom. It's usually short. Be suspicious of anything that tells the AI to ignore earlier instructions, skip asking for permission, or keep something from you.
- List the scripts. Open every file in the folder. If a "writing style" skill ships a Python script that makes network requests, ask why.
- Look for the red flags below. Our free scanner checks for all of them automatically and shows the exact line.
- Pin what you install. Copy the version you reviewed instead of pulling the latest from someone else's repo every time.
Red flags
- Phrases like "ignore previous instructions", "do not tell the user" or "without asking".
- Paths such as
~/.ssh,.aws/credentials, browser profile folders or crypto wallets. - Uploads to webhook relays, paste sites or tunnels (Discord webhooks, pastebin, ngrok and similar).
curl … | shor any "download and run" pattern, and long encoded blobs that get decoded and executed.- Edits to
.bashrc,.zshrc, cron, launch agents or your AI agent's settings files. - Compiled binaries you can't read.
What an automated scan can and can't do
A scanner is fast and never gets bored, so it reliably catches known patterns, including invisible characters a person would miss. What it can't do is judge intent or follow what a script fetches at runtime. Treat a clean scan as "no known red flags", not "proven safe". For a skill that will touch sensitive data or run across a team, a human review is worth it.
The short version
Skills are worth using. Install them the way you'd install a browser extension: from sources you trust, after a quick look at what they ask for, and with a scan to catch what's easy to miss.
Free scan for prompt injection, hidden characters and risky scripts.