PlugMyPlugin
← Browse

skill-security-scan

Zavelinski ★ 0

This skill statically vets untrusted third-party skills before installation by scanning the SKILL.md file, hooks, and settings.json for instruction injection, data exfiltration, dangerous commands, obfuscation, and other security risks, returning an ALLOW/REVIEW/BLOCK verdict with specific remediation advice. It ships an install-guard hook that automatically runs this scan whenever you attempt to install a skill or plugin in Claude Code.

Security DevOps No API key detected runs shell

Install

> /plugin marketplace add Zavelinski/claude-code-skill-security-scan
> /plugin install skill-security-scan

Source: https://github.com/Zavelinski/claude-code-skill-security-scan

What it's made of

1 skill · 1 hook

Commands
0
Agents
0
Skills
1
MCP servers
0
Hooks
1 · UserPromptSubmit

What it needs & plugs into

API keys
none
Paid services
none detected
External tools
node
Talks to
nothing external detected

Analyzed . Facts extracted from the plugin's files. Prose generated by claude-haiku-4-5-20251001.

Is this your plugin?

Claim it to keep the card accurate and enter the weekly contest. Requires signing in as the GitHub owner (Zavelinski).