Brooke Wright
Brooke Wright · @wright_mode
FREE GUIDE

Scan a skill before it touches your files

Three terminal commands, a copy-paste rule for Claude Code, and an honest read on what a scan can and cannot prove. Free, from NVIDIA.

3 commandsCopy-paste readyNo coding neededBuilt by Brooke
Something went wrong. Please try again.

No spam. Unsubscribe anytime.

Three terminal commands that check a skill before you install it Jump to the commands → Join the Membership
Wright Mode — Free Guide

Scan a skill before you install it

Three terminal commands that run NVIDIA's free SkillSpector over any skill you have downloaded, how to read the report, and a rule that makes Claude Code do the check for you.

⚡ Three commands🔓 Free and open source💻 Mac, Windows and Linux🧩 Claude Code and Codex skills

What's inside

This is NVIDIA’s free, open-source SkillSpector. It reads a skill the way an attacker would write one — the instructions, the scripts, the bits hidden in comments — and hands you a report before you install anything. Three commands, all in your terminal.

Download the skill somewhere neutral first. Your Downloads folder is fine. Do not drop it into your agent’s active skills folder (~/.claude/skills or ~/.agents/skills) until the scan is done — once it is in there, Claude can read it on the next prompt.

1

Install the scanner (once)

It runs on uv, a small Python tool manager. If the command below says uv: command not found, install uv from that link first, then come back. This installs the scanner only, not the skill you want to check.

uv tool install git+https://github.com/NVIDIA/skillspector.git
2

Scan the skill

Swap the path for the folder you downloaded. Keep the quotes if the path has spaces. --no-llm runs the static checks only, which is the free, no-account version and the one to start with.

skillspector scan "/path/to/your-skill" --no-llm
3

Save the report so you can actually read it

Same scan, written to a Markdown file you can open, search and keep next to the skill. Scan again any time the skill updates.

skillspector scan "/path/to/your-skill" --no-llm --format markdown --output skill-report.md

What you can point it at

A folder, a single SKILL.md, a GitHub repository URL or a ZIP. Give it the whole bundle where you can — the scripts and helper files are where the interesting stuff hides, and a SKILL.md on its own tells the scanner very little.


A skill is not just a prompt you paste in. It is a folder of instructions and, often, scripts that your agent reads and runs. Whatever access you have given Claude Code or Codex — your files, your API keys, your client folders — a skill works inside that access. A bad one can try to use it.

The part people miss is that the nasty instructions do not have to be visible. Three ways a skill can look clean in a quick preview and still carry instructions you never agreed to:

👁

HTML comments

Rendered previews hide them. The model reads them anyway.

📋

Zero-width characters

Invisible characters inside the text. You cannot see them. The scanner can.

↔

Off-screen whitespace

Text pushed past the edge of the visible area with hundreds of spaces.

How common is this?

A 2026 study (Liu et al., Agent Skills in the Wild) analysed 31,132 public skills and flagged 26.1% for security issues. That figure includes sloppy and ambiguous patterns as well as malicious ones, so it is not “one in four skills is malware” — it is one in four worth a second look before you trust it with your business.


The report has three parts. Read all three — the score on its own is the least useful bit.

1

Risk score out of 100

A summary of what the scanner found, with a severity label. Low is reassuring, not a guarantee. High means stop and read on.

2

Flagged findings

Each one names the file and what triggered it. Open that file and look at the line in context. Ask three questions: does this skill need to read files outside its own folder, does it need to touch credentials or keys, and does it make network requests it never mentions in its description? If the answer to any of those is yes and the skill does not explain why, that is your answer.

3

Install recommendation

The scanner’s own verdict on the next step. Treat it as a second opinion, not a decision made for you.

Worth a closer look

  • A finding about a script the description openly says it runs
  • A flagged word in a README example, not in an instruction
  • Something you can explain after reading the line

Do not install until it is resolved

  • Instructions hidden in comments or invisible characters
  • Reads of API keys, tokens or folders it has no reason to touch
  • Network requests to places the skill never mentions

The optional AI pass

--no-llm skips SkillSpector’s semantic analysis, where a model reads the skill and reasons about intent. It catches things pattern-matching cannot, but it needs a provider set up and sends the skill contents to that provider. NVIDIA’s scanner guide covers the setup. Read what gets shared before you turn it on.


You will not remember to do this by hand every time. So make it the rule. Paste this when you ask Claude Code to install a skill, or drop the one-line version into your CLAUDE.md so it applies to every session.

Before you install this skill for me, do not copy it into my skills folder yet. 1. Download it to a neutral folder (not ~/.claude/skills or ~/.agents/skills). 2. Run: skillspector scan "<that folder>" --no-llm --format markdown --output skill-report.md 3. Show me the risk score, every flagged finding with its file and line, and a plain-English list of what access this skill asks for (files, keys, network). 4. Wait for my go-ahead before installing. If skillspector is not installed, tell me and stop. Do not install it yourself.

The rule for your CLAUDE.md or AGENTS.md:

Never install a skill without first running `skillspector scan --no-llm` on it and showing me the findings. Wait for my approval before copying anything into a skills folder.

Why this works

An agent that installs a skill without looking is exactly the gap a bad skill is written for. Making the scan a standing instruction means the check happens on the boring Tuesday when you are not thinking about it, which is the only time it matters.


I would rather you know the edges now than find them later.

Catches around 70 known patterns across 17 categories: hidden instructions, data exfiltration, credential access, risky code and more
Reads the whole bundle, including scripts, not just the SKILL.md you can see
Gives you something concrete to read before you trust a stranger’s folder with your business
Does not prove a skill is safe. A low score means nothing known was found, not that nothing is there
Does not protect you after install. NVIDIA is clear that scanning does not isolate a skill once it is running
The static pass can miss things and can flag harmless content. Read the findings, do not just read the number

The habit that actually keeps you safe

Anthropic’s own guidance is to only install skills from sources you trust. The scan is what you do on top of that, not instead of it. Trusted source, scan anyway, read the findings, rescan when it updates. Four steps, none of them hard.

Sources checked 17/09/2026: the SkillSpector repository, NVIDIA’s scanner guide and Anthropic’s Use skills in Claude. The commands come straight from the README. They have not been run on your machine, so if one errors, the README is the place to look first.


Ready to go deeper?

Where to go from here.