AI Guides › Playbooks
By Nigel Guy · 7 min read
Someone shares a skill that promises to write your proposals or tidy your inbox, you download the folder, drop it into Claude, and it works. That feels like the end of the story. It isn't: a skill is a set of instructions, and sometimes scripts, written by a stranger, which your AI then follows with your files, your accounts and your permissions. "It worked" tells you nothing about what else it did.
The rule: no skill from outside your own hands gets installed until it has passed a scan you ran yourself, on the exact copy you are about to install, and you have read anything the scan flagged.
This guide walks you through that check using SkillSpector, a free, open-source scanner published by NVIDIA. You do not need to have used a command line before.
| Word | What it means here |
|---|---|
| Skill | A folder with a SKILL.md file (instructions plus a short description) and, optionally, extra files and scripts. Claude Code, Codex CLI and Gemini CLI all use them. |
| Terminal | The text window where you type commands. Terminal on a Mac, PowerShell on Windows. |
| Prompt injection | Hidden or sneaky text that tries to make the AI ignore you and follow the skill author instead. |
| Data exfiltration | Quietly sending your files, keys or passwords somewhere else. |
| Static scan | Reading the files for known bad patterns without running anything. |
| LLM check | Asking an AI model to read the skill's files and judge intent. Optional, and it sends file contents to whichever provider you choose. |
Claude Code's own documentation warns that skills can run shell commands, read and write files, and use an allowed-tools line to pre-approve tools so you are not asked each time. It tells you to review SKILL.md and any bundled scripts before using a third-party skill. A scanner does that first pass for people who can't read the code.
SkillSpector's README cites a 2026 research study ("Agent Skills in the Wild", Liu et al.) that analysed 31,132 skills and found 26.1% contained at least one vulnerability and 5.2% showed likely malicious intent. Those are the study's numbers as reported by NVIDIA; we have not checked the paper itself.
Open Terminal (Mac/Linux) and paste:
curl -LsSf https://astral.sh/uv/install.sh | sh
On Windows, open PowerShell and paste:
powershell -ExecutionPolicy ByPass -c "irm https://astral.sh/uv/install.ps1 | iex"
Alternatives: brew install uv (Mac) or winget install --id=astral-sh.uv -e (Windows). Reopen the window afterwards.
uv tool install git+https://github.com/NVIDIA/skillspector.git
To update later: uv tool update skillspector. To confirm it installed and see every option: skillspector --help. If it says "command not found", close and reopen the terminal.
Download or unzip it somewhere neutral, such as a to-check folder on your Desktop. Do not put it in ~/.claude/skills/ (personal skills) or a project's .claude/skills/ folder yet; those are the places Claude Code loads skills from.
SkillSpector accepts a folder, a single SKILL.md, a Git repository URL or a zip file. It never runs the skill's code. For your first scan, keep everything on your machine with --no-llm:
skillspector scan ./to-check/the-skill/ --no-llm
Other forms that work:
skillspector scan ./to-check/the-skill/SKILL.md --no-llm
skillspector scan ./to-check/the-skill.zip --no-llm
skillspector scan https://github.com/[OWNER]/[REPO] --no-llm
Even with --no-llm, the supply-chain check sends the names and versions of any software packages the skill declares to OSV.dev, a public vulnerability database. It sends package names, not your file contents.
To save a report you can read or share:
skillspector scan ./to-check/the-skill/ --no-llm --format markdown --output report.md
The static scan is fast and repeatable but cannot judge meaning, for example whether a skill's description matches what it actually does. The LLM check can. You choose the provider with an environment variable; if you already use Claude Code, the claude_cli provider uses your existing login rather than an API key:
export SKILLSPECTOR_PROVIDER=claude_cli
skillspector scan ./to-check/the-skill/
Other providers include anthropic, openai, ollama (a model on your own machine) and NVIDIA's nv_build, which is the default and needs an NVIDIA_INFERENCE_KEY. Remember this step sends the skill's file contents to that provider. That is fine for a public skill; think twice for one containing a client's material.
SkillSpector adds points per finding (Critical 50, High 25, Medium 10, Low 5, with a 1.3x multiplier when the skill contains executable scripts), caps at 100, and gives a recommendation:
| Score | Label | What you do |
|---|---|---|
| 0–20 | SAFE | Skim the findings, then install. |
| 21–50 | CAUTION | Read every finding. Install only if each one has an innocent explanation you understand. |
| 51–80 | DO NOT INSTALL | Don't. Look for another skill or ask the author. |
| 81–100 | DO NOT INSTALL | Delete the download. |
Regardless of score, treat any finding about hidden instructions, tool poisoning, credential access or sending data externally as a stop until you understand it. NVIDIA's own scanning guide says hidden instructions should be removed before installing.
If the findings read like jargon, paste the Markdown report into Claude with this prompt. Fill in the skill's stated purpose and paste the report where shown.
You are a cautious security reviewer helping a non-technical person decide whether to install an AI agent skill.
Context: the skill claims to do this: [WHAT_THE_SKILL_SAYS_IT_DOES]. I scanned it with NVIDIA SkillSpector. The full report is below.
[PASTE_REPORT_MD_HERE]
Your task:
1. State the overall score and recommendation exactly as the report gives them.
2. For each finding, explain in one or two plain-English sentences what it means and whether it fits the skill's stated purpose. Label each "explained by purpose", "unclear" or "red flag".
3. List anything I should check by eye in the skill's files, naming the file and line the report points to.
4. Give a final verdict: install, install after a named change, or do not install.
Rules: do not invent findings that are not in the report, and do not downgrade anything the report marks Critical or High. If the report is cut off or the stated purpose is missing, ask me for it instead of guessing. Before answering, check that every finding in the report appears in your list.
Format: a short table of findings, then the verdict in one line.
Move that same folder into place. If you scanned a GitHub URL, download it once, scan the downloaded copy, and install that, because the repository can change between your scan and your install.
Priya runs a two-person bookkeeping practice and is sent a "receipt sorter" skill. She runs step 4: score 35, CAUTION, two findings. One is a Medium "unpinned dependencies" note on a script that reads PDFs; the prompt in step 7 labels it "explained by purpose" and suggests asking the author to pin versions. The other is a High finding that the script posts data to a web address. A receipt sorter has no reason to send anything anywhere, so she treats it as a red flag and doesn't install, despite the overall label being only CAUTION. That gap is the point of the next section.
allowed-tools grants narrow.skillspector --help for current options.