Malicious Code Warning in Claude Skills and Scanner Released
·2026.06.20 05:47
Key point
Multiple malicious payloads that steal credentials have been found within Claude Skills, prompting security warnings.
Details
Security research found 71+ malicious skills in public skill repositories, and Snyk's 'ToxicSkills' audit confirmed 76 credential-stealing payloads.
Installing skills from GitHub and other sources without reviewing the script contents can pose security risks. In response, the following security tools have been released.
- SkillsGuard: An open source project with 151 detection rules (GitHub link)
- Web scanner: Instant scanning available via a
curlcommand without installation
This summary was generated automatically by AI. Check the original for the author's claims and context. Copyright belongs to the original author.
Our guide explains how the AI works. Report summary errors, attribution issues, or removal requests via Contact.