Vetting a skill before you install it
Shared methods · A shared method; linked tool guides explain the exact steps.
This page covers tools outside your selection. You can still read it. Find matching guides
Across 31,132 published skills, 26.1% carried at least one vulnerability. They are not signed, and they steer an agent that already holds your files.
Installing a skill feels like installing a plugin. It is closer to handing someone your unlocked laptop and a list of instructions.
A skill is not a library. It is text that steers an agent which already holds your filesystem, your credentials and your connectors. A malicious package runs code; a malicious skill redirects something that can already run code.
The numbers
A preprint studying 31,132 skills across two major marketplaces found 26.1% contained at least one vulnerability. Snyk's survey of one registry reported prompt injection in 36% of a sample and catalogued over a thousand malicious payloads; a single campaign uploaded roughly 1,200 malicious skills using poisoned metadata.
Two details matter more than the headline percentages:
- Skills are not cryptographically signed. Anyone with a repository can publish one.
- Curation is not a fix. Skills that fetch untrusted third-party content at runtime were 17.7% of one registry — and still 9% of another's curated top 100.
The methods vary and the sampling is not comparable across studies, so treat the exact figures as indicative rather than precise. The direction is not in doubt.
Read it before you install it
Not the README. The actual skill file, every file it references, and every script it ships. If it is too long to read, that is a finding rather than an excuse — and it is exactly the cover a payload wants.
The seven questions
1. Does it fetch anything at runtime? curl, wget, fetch(, pip install, a URL in an instruction. Content fetched later is content nobody reviewed: the skill you read stops being the skill that runs.
2. Where does data go? Any outbound destination — telemetry, a webhook, a gist. A skill has no legitimate reason to send your code anywhere.
3. What does it read? Watch for ~/.ssh, .env, cloud credential files, keychains, browser profiles, shell history. A formatting skill has no business near credentials.
4. What does it pre-approve? A skill can grant itself tools without asking for the turn that invokes it. Bash or Write in that list means an unaudited skill runs commands you will not see.
5. Does the description match the body? Metadata poisoning is a documented technique: a benign description routes it into your session, and the body does something else. Read them against each other.
6. Is anything hidden? Instructions inside code comments, HTML comments, collapsed sections, zero-width characters. The body is a prompt — anything in it is an instruction.
7. What is the update path? A marketplace auto-updates. Today's audit does not cover tomorrow's version. Pin a version, or accept that you are trusting the publisher continuously.
Tools help; they do not decide
NVIDIA publishes SkillSpector, a scanner for exactly this class of problem, and running it is worth the minute it takes. But a scanner detects capabilities — it cannot judge whether a capability is warranted for this skill's stated job. Reading a file is fine in a file-processing skill and alarming in a commit-message skill. That judgement is the actual work.
Try this
Take one skill you already have installed and read it end to end, against the seven questions. Most people find at least one thing they would not have approved if they had looked — and the exercise calibrates you far better than reading about it.
What goes wrong
Trusting curation. A curated top-100 still had 9% fetching third-party content at runtime.
Auditing once, auto-updating forever.
Reading the README instead of the skill. The README is marketing; the skill file is what executes.
Assuming a recognisable publisher is safe. Judge the artefact, not the name.
How to check it worked
Ask what an attacker who controlled this skill's next update could do with the permissions your agent holds. If the answer is worse than you would accept, pin the version or do not install it — better vigilance next time is not a control.
The aiusage-skills library packages this as an agent skill, and ships a validator you can point at anyone else's skills for the parts a machine can check.
Sources
- How Your Credentials Are Leaked by LLM Agent Skills: An Empirical Study (preprint) Tier 2 2026-08-31
- ToxicSkills: malicious AI agent skills — Snyk Tier 3 2026-08-31
- SkillSpector — NVIDIA Tier 1 2026-08-31
- Use Claude Cowork safely — Anthropic Help Center Tier 1 2026-08-31
Something wrong with this page?
Say what you expected and what you got. That is usually the shortest route to a correction, and it goes on the public issue tracker so the fix is visible.