Edge Copy setup link
Docs Are skills safe?
Edge / Docs / Are skills safe?
Safety

Are agent skills safe to install?

What can go wrong with an agent skill, how often it does, what to check, and exactly what Edge checks before it hands one to your agent.

Is it safe to install an agent skill?

Quick answer

Not automatically. A skill is instructions plus optional scripts that your agent follows with your permissions, so a bad one can leak keys or run harmful commands. Snyk found critical issues in 13.4% of 3,984 public skills it scanned in February 2026. Read the files, pin a version, prefer scanned skills and limit what your agent can reach.

Checked 2 October 2026. Edge is our product.

What are the risks of installing a skill?

The Cloud Security Alliance (25 June 2026) groups the risks of Claude agent skills into five areas:

RiskWhat happensWhat to do
Skill sprawlSkills land in folders like ~/.claude/skills with no inventory, so nobody knows what is installed.Keep a list of installed skills; prefer loading per task.
Open registriesAnyone can publish, impersonate a brand, or push a bad update; the same file spreads across registries.Check the publisher and pin an exact revision.
Over-privileged executionA skill inherits everything your agent can reach: tokens, cloud keys, databases.Run agents with the least access the task needs.
Invisible payloadsA few plain-language lines can tell the agent to read a key and post it somewhere. No code needed.Read SKILL.md itself, not only the scripts.
Cross-platform spreadThe same SKILL.md works in Claude Code, Codex, Cursor and more, and scan results do not travel with it.Re-check a skill where you use it.

How common are unsafe skills?

Snyk's ToxicSkills audit scanned 3,984 skills from ClawHub and skills.sh as of 5 February 2026. It found at least one critical-level issue, such as malware, prompt injection or exposed secrets, in 13.4% of them (534 skills), and at least one security flaw of any severity in 36.82% (1,467 skills). Cloud Security Partners cites the same 13.4% figure.

Those numbers describe what was public then, not any one directory today. They are a reason to check, not a reason to avoid skills altogether.

What should I check before I install a skill?

  • Read SKILL.md. Look for instructions to send data anywhere, read keys or files outside the task, or hide steps from you.
  • Read the scripts. Note network calls and the hosts they reach, package installs, and anything that downloads and runs code.
  • Pin a revision. Use an exact commit so a later update cannot change what you approved.
  • Check the publisher. A known organisation, a licence and a history are good signs; their absence is a reason to slow down.
  • Look for current scan evidence. Prefer a recent scan of the same files, and know what the scanner covers.
  • Limit access. Do not run a new skill with production credentials. Try it first on a small, low-stakes task.

The skill selection guide walks through these steps with Edge's evidence pages.

How does Edge screen a skill?

This is what the code does under load policy 2026-09-27.1, read from the edge-mcp repository on 2 October 2026.

  • One fingerprint for the exact files. Edge hashes every file in the skill folder (path, executable flag and SHA-256) into one package hash, tied to a git commit. Every check must match that hash. Code.
  • Its own static checks. Rules flag a remote script piped into a shell, decoded payloads that get executed, reverse shells, crypto miners, credential reads next to network sends, environment dumps, request-capture hosts, instruction-override phrasing aimed at the agent, instructions to hide actions from the user, hidden Unicode, shipped binaries and archives, symlinks that leave the package, destructive commands and persistence. Rules.
  • A secrets check. A committed secret in the bundle is a high-severity failure. Code.
  • More scanners for the catalog. Edge's catalog pipeline also runs Cisco's skill-scanner and Semgrep on the same package.
  • Outside reports can block, not approve. Reports from outside scanners can stop a skill, but only Edge's own checks of the exact files can clear it.
RuleResult
Any high or critical finding from any scannerBlocked
Two scanners fail itBlocked
Checks older than 30 days, or for another revisionWaits for a new check
Edge's own checks of the exact files passCan be loaded, shown as reviewed
Running commands or calling an APIRecorded as a capability, never a failure on its own

At load time Edge reuses a current check of those exact files or runs one; if the result does not meet the policy, the skill is not loaded. The states your agent sees are explained on Safety.

What does Edge not do?

  • It does not promise safety. "Reviewed" means current automated checks met the policy, nothing more.
  • Its static rules match known patterns. As the Cloud Security Alliance notes, plain-language instructions can get past pattern matching; read what your agent will follow.
  • It does not run or sandbox skills. Your agent runs commands with the permissions you gave it.
  • It screens public catalog skills. Skills already on your machine are yours to check; the local connector can scan one.

Common questions

Are Claude skills safe?

Some are and some are not. Snyk's February 2026 audit of 3,984 skills from ClawHub and skills.sh found at least one critical issue in 13.4% of them. Treat a skill like code from the internet: read it before your agent follows it.

Does a security scan make a skill safe?

No. Scanners find known patterns. The Cloud Security Alliance notes that plain-language instructions in a SKILL.md can tell an agent to send out keys without any code a scanner would flag.

Does Edge run or sandbox skills?

No. Edge hands your agent the instructions and files for the current task. Your agent decides what to run, with the permissions you gave it.

What does Edge do when a skill fails its checks?

It withholds it. A high or critical finding from any scanner, failures from two scanners, or a committed secret blocks the skill. Old or mismatched evidence means it waits for a new check.

Sources and method

External figures are quoted from their publishers and dated. Edge's behaviour is described from its source code at commit 62b771a, not from marketing copy. Edge is our product.