Claude Skills explained: a library of instructions, tools and plugins
Claude Skills security: instruction trust and installer replacement
Review both the words an agent will follow and the files a helper script can overwrite
What you will learn
- Treat instructions as untrusted input
- Bound installation writes
- Review distributed copies
Before you start
- A disposable project
- A pinned repository revision
- One supported agent client
Turn a catalogue entry into a measured, reversible team decision
Key takeaways
- Instruction text can steer privileged agent tools.
- The installer replaces same-name files.
- A marketplace listing is not a sandbox.
Treat instructions as untrusted input
A skill can ask an agent to read data, call tools, alter files or contact services. A well-formatted SKILL.md is not a security guarantee; its scripts and references deserve the same review as a dependency.
Start with a disposable repository and no production secrets. Watch for network calls, shell pipelines, credential reads and instructions that claim priority over your organization’s own policy.
Bound installation writes
The pinned Codex installer accepts a configurable destination root and removes an existing same-name skill before copying. A mistaken destination can replace customized material; `--all` increases the scope of that risk.
Use `--dry-run`, resolve the target path, inspect local modifications and keep a backup. Do not interpret a successful copy as evidence that the skill is safe to activate.
Review distributed copies
Windows symlink handling can produce dead one-line pointers. Conversely, `cp -rL` intentionally follows source links; verify the resulting tree and any executable bits. Marketplace updates and converted rules require their own review.
We did not sandbox, execute or penetration-test this collection. The safe conclusion is a review checklist and a narrow pilot, not a blanket endorsement of every package in the repository.
Decision guide
| Criterion | Option A | Option B |
|---|---|---|
| Best when | You need predictable behavior and easy auditing | You need adaptive optimization and have reliable telemetry |
| Main risk | May leave performance on the table | Can become difficult to explain or debug |
Implementation steps
- 1
Review SKILL.md, scripts, references and network calls.
- 2
Dry-run and snapshot the exact installation destination.
- 3
Test one skill without sensitive data or broad permissions.
Copy-ready example
untrusted package -> code/content review -> scoped install
scoped agent -> disposable task -> observed effects -> approvalFrequently asked questions
Does the repo license make each skill safe to run?
No. Licensing and operational security answer different questions.
Can I use `--all` for a security review?
It expands scope before you know which skills matter. Review and install a narrow selection first.
Sources
- Claude Skills / scripts/codex-install.shSource checked 2026-10-04
- Claude Skills / INSTALLATION.mdSource checked 2026-10-04
- Claude Skills / README.mdSource checked 2026-10-04
- Claude Skills / LICENSESource checked 2026-10-04
- Claude Skills / engineering/agent-harness/skills/agent-harness/SKILL.mdSource checked 2026-10-04