Skip to content
anavem.com

ExplainerPublished 8 min read

Are Claude Skills Safe? What a Skill Can Contain and Run

What Anthropic's docs say a Claude Skill can contain and run, where its scripts execute, what review they advise, and a checklist before you turn one on.

By Emanuel DE ALMEIDA · Editor

In this article
  1. How this article was made
  2. What the sources say: what a skill can contain
  3. What the sources say: where skill code runs
  4. What the sources say: Anthropic's security guidance
  5. What the sources say: Anthropic's enterprise review table
  6. What the sources say: sharing, data and licences
  7. What to consider: a checklist before you turn a skill on
  8. Limitations, and when not to use a skill
Editorial evidence card for Are Claude Skills Safe? What a Skill Can Contain and Run

Key takeaways

Documented
  • Answer: What Anthropic's docs say a Claude Skill can contain and run, where its scripts execute, what review they advise, and a checklist before you turn one on.
  • Evidence: Based on 8 dated primary or official sources, most recently checked .
  • Scope: This article does not claim hands-on testing. Performance or safety verdicts require a linked test record.

No page can tell you that a particular Claude Skill is safe or unsafe. Anthropic's documentation says to use skills only from trusted sources and to treat installing a skill like installing software, because a skill can include instructions and code. This article lists what Anthropic says a skill can contain, where it runs, and a checklist for reviewing one.

How this article was made

We fetched and read the pages listed in the sources on 2026-10-03: Anthropic's platform, claude.com, Help Center and Claude Code documentation, plus the public skills repository. We did not test any skill, and Anavem has not audited any skill. We did not use any third-party count of malicious skills, because we did not open an original report. Passages are labeled "What the sources say" and "What to consider" (our assessment).

What the sources say: what a skill can contain

The Agent Skills overview says a skill is a directory with a SKILL.md file of instructions. It can also bundle:

  • more markdown files with specialized guidance
  • executable scripts that Claude runs using bash
  • reference material such as database schemas, API documentation, templates or examples

Claude reads SKILL.md when a request matches the skill's description, and opens other files when the instructions point to them. When Claude runs a script, the docs say only the script's output enters context.

The guide Create custom skills says a skill can include scripts in any language available where it runs. In Claude Code that is whatever is installed on your machine. On claude.ai the skill's folder, scripts included, is copied into the code execution sandbox. The guide also tells authors not to put API keys or passwords in a skill, because everyone the skill is shared with receives its files.

What the sources say: where skill code runs

According to the platform documentation, read 2026-10-03:

  • Claude API: skills run in a sandboxed container with no network access and no runtime package installation.
  • claude.ai: network access varies. Depending on user and admin settings, skills may have full, partial or no network access.
  • Claude Code: skills have the same network access as any other program on your computer.

On Claude Code, the skills page describes two features worth knowing before you read a skill. The allowed-tools field grants permission for the listed tools during the turn that invokes the skill, so Claude can use them without prompting you. A shell-command syntax in a skill runs commands before the skill content is sent to Claude.

The Claude Code page on plugin security states that skills, commands and agents in a plugin enter Claude's context as instructions that influence what Claude does with the tools it already has. In the same plugin, hooks and servers can run code on your machine.

What the sources say: Anthropic's security guidance

The platform documentation's security section says to use skills only from trusted sources: ones you created or obtained from Anthropic. It says a malicious skill can direct Claude to invoke tools or run code in ways that do not match the skill's stated purpose, and that depending on the access Claude has, malicious skills could lead to data exfiltration, unauthorized system access or other risks. Its key points:

  • Audit thoroughly. Review every bundled file: SKILL.md, scripts, images and other resources. Look for unexpected network calls, file access patterns or operations that do not match the stated purpose.
  • External sources are risky. Skills that fetch data from external URLs pose particular risk, because fetched content may contain malicious instructions, and a trustworthy skill can be compromised if its external dependencies change.
  • Tool misuse and data exposure. Skills can invoke file operations, bash commands and code execution, and a skill with access to sensitive data could be designed to leak it.
  • Treat it like installing software, especially around production systems with sensitive data.

The claude.com skills page says, on the Turn on step, that a skill's instructions and any scripts it carries run as part of your conversation, and that skills shared with you or uploaded by you are not reviewed by Anthropic. It tells you to open the skill and read SKILL.md and its files before turning it on. The Help Center article Use skills in Claude says to install skills only from trusted sources and names prompt injection and data exfiltration as the primary risks.

What the sources say: Anthropic's enterprise review table

The page Skills for enterprise gives a risk table for admins. Its concern levels are Anthropic's, copied here.

What to look for Anthropic's concern level Reason given
Scripts in the skill directory (.py, .sh, .js) High Scripts run with full environment access
Directives to ignore safety rules, hide actions or change behavior conditionally High Can bypass security controls
Instructions that reference MCP tools High Extends access beyond the skill itself
URLs, API endpoints, fetch, curl or requests calls High Potential data exfiltration vector
API keys, tokens or passwords in skill files High Secrets exposed in Git history and context window
Paths outside the skill directory, broad globs, path traversal Medium May access unintended data
Instructions that direct Claude to use bash or file operations Medium Review what operations are performed

Source: platform.claude.com, "Skills for enterprise," read 2026-10-03.

The same page has an eight-step review checklist. In short: read all skill content, check that script behavior matches the stated purpose (run in a sandbox), check for adversarial instructions, search for network calls, check for hardcoded credentials, list the tools and commands the skill tells Claude to use, confirm where external URLs lead, and look for patterns that read sensitive data and then send or encode it. The page warns never to deploy skills from untrusted sources without a full audit.

It also describes skill content scanning. Claude Enterprise organizations can turn it on for custom skills uploaded in claude.ai and Claude Cowork. A skill that fails the scan, or whose scan has not finished, is blocked. The page says scanning does not cover skills uploaded through the Skills API, skills already in the organization when scanning was turned on, or organizations with certain data-handling configurations. It states that scanning complements, but does not replace, the review checklist.

What the sources say: sharing, data and licences

The Help Center article says that on Team and Enterprise plans you can share skills with colleagues, and that the skill sharing toggle is on by default for Team plans and for Enterprise plans that have not set a skills preference. It also says the Share with organization and Share with groups toggles are off by default, and an Owner must enable at least one before the Share button appears. For organizations with HIPAA readiness or other regulated configurations, it says skills and skill sharing are off by default.

The platform page says Agent Skills is not covered by zero data retention arrangements. Anthropic's skills repository describes its skills as provided for demonstration and educational purposes, says to test skills in your own environment before relying on them, and says some document skills are source-available rather than open source.

What to consider: a checklist before you turn a skill on

This checklist is ours, built from the sources above. It does not make a skill safe, and Anavem has not audited any skill.

  1. Where did it come from? Prefer skills you wrote or got from Anthropic. For anything else, find the author and the original repository.
  2. Can you read every file? Open the folder, not just SKILL.md. Include scripts, references and assets.
  3. Are there scripts? If yes, read them. Ask what each one reads, writes, installs or sends.
  4. Any web addresses? List every URL and every fetch, curl or requests call. Ask who controls each address and whether the content could change.
  5. Any odd instructions? Look for text that tells Claude to hide actions, ignore rules or behave differently in certain cases.
  6. What access will Claude have when it runs? On claude.ai, check your network and code execution settings. On Claude Code, remember it has your computer's network access. Check any allowed-tools line.
  7. What data could it touch? Do not turn on an unreviewed skill in a conversation or folder that holds sensitive files.
  8. Any credentials inside? There should be none. Do not paste your own into a skill.
  9. Is it pinned? If you load it from a repository, note the version you read, because updates can change the files you reviewed.
  10. Can you turn it off? Know where to switch it off (Customize > Skills) and how to remove it.

Limitations, and when not to use a skill

  • The documentation describes risks and review steps. It does not give the likelihood of any problem.
  • Menu names and plan rules differ between Anthropic pages, as covered in Claude Skills explained.
  • If you cannot read a skill's files, do not understand its scripts, or do not trust where it came from, the checklist points to leaving it off. That is our assessment.
  • A skill that works inside an organization may need that organization's review process. The enterprise page describes one.

Related reading: the terminology map, are MCP servers safe, and Anavem's Claude skill listings. The Claude Code profile covers the tool that runs skills on your computer.

Tools mentioned

Sources

Get new guides by email

New verified tool profiles, tested workflows and pricing changes. Sponsored items are labelled.