# Anthropic skill scanner bypassed: malicious skills marked safe

> Three simple tricks got malicious Claude skills past Anthropic's upload-time scanner.

- **Severity:** Medium: Real and reproducible, but needs unusual setup, user help or a narrow audience. Plan a fix.
- **Category:** Attack, Supply chain
- **Published by:** AIR Security
- **Disclosed:** 2026-09-24
- **Affects:** Claude organization skills, Anthropic skill and plugin scanning
- **Research by:** Alon Loewenstein, Ofir Birka, Shay Lempert
- **Primary source:** https://www.air.security/blog-posts/anthropic-scanner
- **Page:** https://theinjection.dev/items/air-anthropic-skill-scanner-bypass/

AIR Security researchers say Anthropic's skill and plugin scanner for Claude organization skills marked malicious skills as safe, using look-alike domains, an unclaimed PyPI dependency and an obfuscated binary.

## What happened

AIR Security tested Anthropic's skill and plugin scanner for Claude organization skills, which Anthropic released on August 6, 2026. The researchers ran thousands of skills through it and published three bypasses on September 24, 2026.

## How it works

AIR describes the scanner as a static structural analyzer plus an LLM that checks a skill once, at upload time. A skill that pipes a script from the look-alike domain ntn.sh instead of ntn.dev was marked safe. A real-world skill that depends on the unclaimed PyPI name nodriver-kit was not flagged, and an obfuscated binary that steals SSH keys confused the LLM reviewer.

## Who is affected

Organizations that rely on the scanner to vet skills uploaded to Claude. Anthropic's help page says scanning turns on automatically for Enterprise organizations on October 2, 2026.

## What to do

Treat a scanner pass as one signal, not approval. Check every external domain, package and binary a skill references, and rescan skills over time, since a verdict only reflects the moment of upload.

## Sources

1. [AIR Write-up](https://www.air.security/blog-posts/anthropic-scanner)
2. [Anthropic Scanner Docs](https://support.claude.com/en/articles/15927065-get-started-with-skill-and-plugin-scanning)
3. [OWASP Skills Top 10](https://owasp.github.io/www-project-agentic-skills-top-10/)
