The three commands
This is NVIDIA’s free, open-source SkillSpector. It reads a skill the way an attacker would write one — the instructions, the scripts, the bits hidden in comments — and hands you a report before you install anything. Three commands, all in your terminal.
Download the skill somewhere neutral first. Your Downloads folder is fine. Do not drop it into your agent’s active skills folder (~/.claude/skills or ~/.agents/skills) until the scan is done — once it is in there, Claude can read it on the next prompt.
Install the scanner (once)
It runs on uv, a small Python tool manager. If the command below says uv: command not found, install uv from that link first, then come back. This installs the scanner only, not the skill you want to check.
Scan the skill
Swap the path for the folder you downloaded. Keep the quotes if the path has spaces. --no-llm runs the static checks only, which is the free, no-account version and the one to start with.
Save the report so you can actually read it
Same scan, written to a Markdown file you can open, search and keep next to the skill. Scan again any time the skill updates.
What you can point it at
A folder, a single SKILL.md, a GitHub repository URL or a ZIP. Give it the whole bundle where you can — the scripts and helper files are where the interesting stuff hides, and a SKILL.md on its own tells the scanner very little.
What a skill can actually do
A skill is not just a prompt you paste in. It is a folder of instructions and, often, scripts that your agent reads and runs. Whatever access you have given Claude Code or Codex — your files, your API keys, your client folders — a skill works inside that access. A bad one can try to use it.
The part people miss is that the nasty instructions do not have to be visible. Three ways a skill can look clean in a quick preview and still carry instructions you never agreed to:
HTML comments
Rendered previews hide them. The model reads them anyway.
Zero-width characters
Invisible characters inside the text. You cannot see them. The scanner can.
Off-screen whitespace
Text pushed past the edge of the visible area with hundreds of spaces.
How common is this?
A 2026 study (Liu et al., Agent Skills in the Wild) analysed 31,132 public skills and flagged 26.1% for security issues. That figure includes sloppy and ambiguous patterns as well as malicious ones, so it is not “one in four skills is malware” — it is one in four worth a second look before you trust it with your business.
How to read the report
The report has three parts. Read all three — the score on its own is the least useful bit.
Risk score out of 100
A summary of what the scanner found, with a severity label. Low is reassuring, not a guarantee. High means stop and read on.
Flagged findings
Each one names the file and what triggered it. Open that file and look at the line in context. Ask three questions: does this skill need to read files outside its own folder, does it need to touch credentials or keys, and does it make network requests it never mentions in its description? If the answer to any of those is yes and the skill does not explain why, that is your answer.
Install recommendation
The scanner’s own verdict on the next step. Treat it as a second opinion, not a decision made for you.
Worth a closer look
- A finding about a script the description openly says it runs
- A flagged word in a README example, not in an instruction
- Something you can explain after reading the line
Do not install until it is resolved
- Instructions hidden in comments or invisible characters
- Reads of API keys, tokens or folders it has no reason to touch
- Network requests to places the skill never mentions
The optional AI pass
--no-llm skips SkillSpector’s semantic analysis, where a model reads the skill and reasons about intent. It catches things pattern-matching cannot, but it needs a provider set up and sends the skill contents to that provider. NVIDIA’s scanner guide covers the setup. Read what gets shared before you turn it on.
Make Claude Code scan before it installs
You will not remember to do this by hand every time. So make it the rule. Paste this when you ask Claude Code to install a skill, or drop the one-line version into your CLAUDE.md so it applies to every session.
The rule for your CLAUDE.md or AGENTS.md:
Why this works
An agent that installs a skill without looking is exactly the gap a bad skill is written for. Making the scan a standing instruction means the check happens on the boring Tuesday when you are not thinking about it, which is the only time it matters.
What a scan does not prove
I would rather you know the edges now than find them later.
The habit that actually keeps you safe
Anthropic’s own guidance is to only install skills from sources you trust. The scan is what you do on top of that, not instead of it. Trusted source, scan anyway, read the findings, rescan when it updates. Four steps, none of them hard.
Sources checked 17/09/2026: the SkillSpector repository, NVIDIA’s scanner guide and Anthropic’s Use skills in Claude. The commands come straight from the README. They have not been run on your machine, so if one errors, the README is the place to look first.
Ready to go deeper?
Where to go from here.
Wright Mode Membership
Join a community of women entrepreneurs implementing AI and automation in their businesses. Live calls, templates, and ongoing support.
Claude Masterclass
Learn how to use Claude like a pro. From prompting fundamentals to building real workflows that save hours every week.
Claude Code Masterclass
Go beyond the chat interface. Build automations, process data, and create tools with Claude Code — no developer experience needed.