Skill Security Audit

Security audit workflow for vetting third-party Claude Skills, plugins, slash commands, agent definitions, hooks, and MCP configs for malicious content BEFORE they get installed or enabled. Use this whenever the user mentions installing, downloading, trying out, reviewing, or vetting any skill or plugin from a marketplace or repo (ClawHub, skills.sh, GitHub, npm, a pasted URL or zip), asks whether a skill is safe or trustworthy, says "check this skill out" or "should I add this" — even if they never say the words security or audit. Also use before enabling any skill file that did not originate on this machine, and when re-checking third-party skills that are already installed. Never install first and audit later — run this workflow first.

LcplYoohoo Updated

File contents

LcplYoohoo/claude-skills/tree/main/skills/skill-security-audit commit eff6b38fa3

Frequently asked questions

npx skillmds@latest add lcplyoohoo/skill-security-audit