Back to skill

Security audit

Claude Code

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed local Claude Code documentation helper with a simple installer and no evidence of hidden data access, network activity, or automatic code execution.

This looks safe to install if you want a local Claude Code documentation helper. Be aware that some documentation examples mention installing Claude Code or configuring MCP servers; treat those as separate actions and review their permissions before running them.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
83% confidence
Finding
The skill’s invocation guidance is broad and everyday in nature, such as using it whenever users want help with coding tasks or complex programming tasks. Overbroad triggers can cause the skill to be selected in many normal development conversations, unnecessarily expanding exposure to its execution-oriented features and increasing the chance of risky or unintended activation.

Static analysis

No suspicious patterns detected.