Security matters because skills can shape agent behavior, suggest commands, and include supporting files. Start with high-grade skills and review source before installation.
Indexed skills
36646
Search focus
Claude skill
Security context
Scanned
Grade-A skills have the strongest security scan results in Skills Directory. They are not a guarantee, but they are a better starting point than unreviewed random GitHub snippets.
Common risk categories include prompt injection, credential theft, suspicious network calls, destructive shell commands, hidden files, obfuscation, and unsafe persistence.
Security scans reduce risk, but you should still inspect source, understand commands, and avoid installing skills that request unnecessary access.
Skills can influence agent behavior, suggest commands, include helper files, or touch code and data. Skills Directory adds security context so you can inspect risk before installing a workflow from a public repo.
See the security modelNo security grade is a guarantee. Grade A means the automated scan found fewer or lower-severity risk signals, but human review is still recommended.
Check source repo, author, files, commands, network behavior, credential handling, and whether the skill asks for permissions it does not need.
Skills can include malicious or risky instructions and supporting files. That is why security scanning and source review are important.