seoskills.sh
Catalog/Docs/Claude skills security: risks and what to check

Are Claude skills safe? How to check one before you install

Updated

A Claude skill is as safe as the instructions and scripts inside it. Your agent carries out a skill with its own tools and your permissions, and any script the skill ships runs on your machine, so treat a skill like third-party code and read it before you install. Most of what matters sits in four places: the SKILL.md, its scripts, its allowed-tools line, and where it sends data.

What a skill can do on your machine

A skill doesn't run by itself. Your agent reads it and acts on it with its usual tools: reading and editing files, running shell commands, fetching web pages. Your permission settings decide which actions need your approval, and a script in the skill's scripts/ folder runs like any other command. By default, Claude can also load an installed skill on its own when a task matches its description.

In Claude Code, read these three features closely:

  • allowed-tools pre-approves tools for the turn that invokes the skill, so Claude can use them without asking you. A scoped entry such as Bash(git status *) covers one command; a bare Bash covers any shell command. The grant ends when you send your next message, and your deny and ask rules still override it. Workspace trust doesn't gate this field, so review the allowed-tools of skills checked into a repository before you run Claude Code there.
  • Inline commands. A command written as !`command` runs before Claude reads the skill, and its output replaces it. It never prompts you. If the skill's allowed-tools or your own rules allow it, it runs; deny rules still win, and outside auto mode anything not allowed aborts the skill.
  • Hooks. A skill's frontmatter can register hooks that keep running for the rest of the session once the skill is invoked.

What to check before you install

Use this list for any skill you didn't write. How to write a SKILL.md file explains each part.

  1. Read the SKILL.md from top to bottom. Watch for instructions to hide actions from you, ignore other instructions, skip confirmations, or edit agent config files such as CLAUDE.md.
  2. Open every script. Check what it reads, what it writes, and what it downloads or runs.
  3. Read allowed-tools. Scoped entries are narrow. A bare Bash, or a web tool such as WebFetch, should match a clear need in the instructions.
  4. Find every URL. Know which hosts the skill calls and what it sends. Calling the Search Console API is normal for an SEO skill; posting files or environment variables to an unfamiliar host isn't.
  5. Check credentials and scopes. Content Decay Predictor, for example, needs Google credentials with the read-only Search Console scope. A skill that asks you to paste a password into chat, or reads ~/.ssh, deserves a hard look.
  6. Look at the author and the repo. Note who maintains it, how recently it changed, and whether what you install is what you read.
  7. Check the license. The license field or the repo's license file tells you whether you may use and change the skill.

Check again after updates. npx skills update moves installed skills to their latest versions, so the skill you read last month may not be the one you run today.

You can also limit a skill without editing it. In Claude Code, setting it to "user-invocable-only" under skillOverrides in settings stops Claude from starting it on its own, and a deny rule such as Skill(deploy *) blocks it. Setting "disableSkillShellExecution": true stops inline commands in user, project and plugin skills.

What the seoskills.sh scan looks for

Every listed skill's SKILL.md gets a static, pattern-based scan, and so do the bundled files of the other authors' skills we serve as archives. The rules fall into six groups:

GroupWhat it looks for
Download and runDownloads piped into a shell or interpreter, files downloaded and run in one line, fetched code passed to eval, packages installed from a URL or git link, code that runs strings as shell commands
Destructive commandsRecursive force deletes, git force pushes and hard resets, dropped or truncated database tables, disk wipes, world-writable permissions
Credential requestsAsking you to paste or share an API key, token, password or cookie; reading SSH keys or files like ~/.aws/credentials, .netrc and .npmrc
Data leaving the machineKnown paste, webhook and tunnel hosts, environment variables sent over the network, curl uploads, and instructions to send files, the repo, secrets or the conversation to a URL
Prompt injection and hidden content"Ignore previous instructions", hiding actions from the user, role overrides, edits to agent config such as CLAUDE.md or AGENTS.md, long base64 blobs, decode calls, invisible Unicode characters
Safety offFlags that skip permission prompts or disable sandboxes, sudo, skipping confirmation, and bypassing captchas, bot detection, rate limits, robots.txt or authentication

Skill pages show the result as a count of matches and the date checked.

What the scan doesn't do

It reads text. It doesn't run code, follow links, or judge whether a skill's SEO advice is any good. A match means "read this part before you install", not "malicious". A skill that shows curl -X POST to call an API matches the upload rule even when the call is harmless, and reviewed false positives exist. A clean result means none of these patterns appeared, nothing more.

To cut false positives, the scan skips credential-like environment variable names, HTML comments, installs of a named package, and Google credential files such as credentials.json, which SEO skills use for API access. It doesn't scan allowed-tools; pages label broad grants instead.

How seoskills.sh reviews new and changed skills

  • New skills. A daily sync searches skills.sh for SEO skills. Skills seen for the first time go into a review queue and stay hidden until someone reads and approves them for relevance to SEO, substance and the scan result. Off-topic, thin and duplicate skills are dropped.
  • Changed skills. When a listed skill changes upstream and the new version adds a risky pattern the old one didn't have, the change is held. The last reviewed version keeps serving, and the page says an update is pending review.
  • Removed or renamed skills are archived: the page goes away or redirects to its replacement.
  • Labels and notes. Pages label skills whose allowed-tools pre-approve unrestricted shell access ("Runs shell commands") or web access ("Fetches web pages"). Some add notes on shared files a single-skill install doesn't copy, independent security reviews, or sandbox warnings.
  • Digests. Installs from our index, such as npx skills add https://seoskills.sh --skill content-decay-predictor, carry a sha256 digest that the skills CLI checks before installing.

A hold covers what seoskills.sh serves. The command on another author's skill page installs from their GitHub repository as it is when you run it, so if the page says an update is pending review, read the repo's current version first.

Report a problem

Report a security problem in a listed skill or in the site privately, not in a public issue. Our security page links to private vulnerability reporting on the catalog repo. Include the skill's page URL and what you found.

Next