AI Briefing
KO

Malicious Code Warning in Claude Skills and Scanner Released

·2026.06.20 05:47

Key point

Multiple malicious payloads that steal credentials have been found within Claude Skills, prompting security warnings.

Details

Security research found 71+ malicious skills in public skill repositories, and Snyk's 'ToxicSkills' audit confirmed 76 credential-stealing payloads.

Installing skills from GitHub and other sources without reviewing the script contents can pose security risks. In response, the following security tools have been released.

  • SkillsGuard: An open source project with 151 detection rules (GitHub link)
  • Web scanner: Instant scanning available via a curl command without installation

This summary was generated automatically by AI. Check the original for the author's claims and context. Copyright belongs to the original author.

Our guide explains how the AI works. Report summary errors, attribution issues, or removal requests via Contact.