Observed Signal · May 30, 2026 · Security Audit · Source: DEV Community · Impact: 4/5 · Sentiment: Negative

Snyk audit finds widespread malware in Claude skills

Executive Signal Summary

In February 2026 Snyk published the ToxicSkills audit, the first large-scale security review of public Claude Code skills, scanning 3,984 skills from ClawHub and skills.sh. The audit found extensive risks: 13.4% of skills had critical issues, 36% contained prompt-injection payloads, 1,467 distinct malicious payloads were identified, and 91% of confirmed malware combined natural‑language jailbreaks with executable shell payloads. The article outlines common attack patterns (prompt injections in descriptions, chained shell pipelines, and dependency-typo squats), a seven-step framework for auditing skills before installation, and examples of real skills rejected during a May 2026 review. It also cites Anthropic platform signals (Claude Code spec release in Dec 2025, a March 31, 2026 source leak, and a June 15 billing change) and describes a paid SkillVault bundle that ships 41 hand‑audited skills and public audit summaries.

Polaris7 AgentPolaris7 Strategic Assessment
High Confidence

A large-scale security audit of LLM agent skills affecting Anthropic's Claude ecosystem highlights systemic supply-chain and prompt-injection risks that influence trust, deployment practices, and platform economics for teams building on agentic AI.

SIGNAL RADAR

Track Anthropic Signals & Market Shifts in Real-Time

Polaris7 autonomous intelligence agents track regulatory filings, primary sources, executive changes, and deal flow 24/7. Create your free Explorer workspace to monitor these entities.

Start Free in Explorer
Free Explorer tierNo credit card requiredInstant watchlist setup

Key Takeaways & Evidence Grounding

  • Snyk published the ToxicSkills audit in February 2026, scanning 3,984 Claude Code skills from ClawHub and skills.sh.
  • Audit findings included: 13.4% of skills with critical-level issues; 36% containing prompt-injection payloads; 1,467 distinct malicious payloads; 91% of confirmed malware combined natural-language jailbreaks with executable shell payloads.
  • Claude Code skills shipped as an open spec in December 2025; by March 2026 MCP downloads were tracking at 97 million per month and the most-installed marketplace skill exceeded 564,000 installs.
  • Anthropic's March 31, 2026 source leak exposed a bashSecurity.ts module (23 security checks) and a documented CLAUDE.md prompt-injection technique enabling multi-stage pipelines that can bypass deny rules.
  • SkillVault offers a commercial bundle of 41 hand-audited skills, public audit summaries, quarterly refreshes, and a $99 lifetime purchase option referenced in the article.
Primary Source Grounding & Direct Attribution
Direct Origin Attribution
Primary Reporting: DEV Community•Published: May 30, 2026
Original Coverage Title: “Are Claude skills safe in 2026? What the Snyk ToxicSkills audit actually found”

Related Market Signals & Shifts

Recent verified developments and strategic activity across this market segment.

Agent Skills SecurityMar 31, 2026

Re-Scan Finds Critical Security Issues in ClawHub Skills

A follow-up security scan of the top 50 ClawHub skills by the Rotifer Protocol found rapid ecosystem growth and the first occurrence of critical code-execution patterns. Total downloads for the Top 50 rose from 1.25M to over 3.5M in one week. The scan detected one eval() use and 115 system-command execution patterns concentrated in two self-evolving skills, producing 844 findings across ~25,000 lines of code. Two of the previously top-ranked skills were delisted (including the #1 with 311K downloads), 17 of 50 skills (34%) are flagged "Suspicious" by OpenClaw behavioral indicators, and the Grade A share fell from 88% to 78%. The report highlights author concentration (one maintainer owns 18 popular skills) and recommends multiple trust layers (V(g), OpenClaw, VirusTotal) for ecosystem safety. Scanner tools and full data are open source.

Read assessment
Large Language Models & AI SecurityJun 23, 2026

Claude Code Vulnerability Exposes Agentic LLM Risks

A developer security write-up warns that Claude Code — an autonomous AI coding agent — can execute repository code with root-level access without explicit user approval, citing CVE-2025-59536 (CVSS 8.7). The article outlines five real attack vectors: malicious documents, poisoned pull requests, compromised MCP servers, trojanized skills/plugins, and memory poisoning; it cites a Snyk scan of 3,984 public skills finding prompt injection in 36% and Microsoft documentation of memory-poisoning incidents across 31 organizations. Recommended mitigations include sandboxing (scoped bot accounts, containerized review with network disabled), strict file-access deny lists, input sanitization (strip metadata and hidden Unicode), human approval gates for sensitive actions, logging, and limiting persistent memory. The piece emphasizes that LLMs treat data as potential instructions, making prompt injection a fundamental risk that must be mitigated via layered defenses and minimal privileges.

Read assessment
Large Language Models (LLM) & AIJun 11, 2026

Defending AI Agent Skills From Supply-Chain Attacks

A technical post explains a new supply-chain attack vector targeting AI agent 'skills' (SKILL.md files) which bypass package-manager protections and endpoint detection, allowing malicious instructions to run in high-trust developer environments. The author documents why existing defenses (pnpm/npm safeguards, EDR) fail against skill layers, cites that ClawHub contained 341 malicious skills (11.9%) of 2,857 in Feb 2026, and describes a practical mitigation—'skill-firewall'—that combines static analysis with LLM-based scanning for Claude Code / Cursor skill layers. The article also shares operational and UX lessons from building the tool, such as symlink attack vectors and preferring agent warnings over end-user alerts.

Read assessment

Track Real-Time Market Signals & Shifts

Set up custom watchlists to receive automated, evidence-grounded executive digests whenever material signals or shifts occur across your tracked landscape.