Skip to content
The Injection_
LIVE
LIVElast sweep UTCnext in--:--:--

[ RSS ][ JSON ][ llms.txt ]

Anthropic skill scanner bypassed: malicious skills marked safe

Three simple tricks got malicious Claude skills past Anthropic's upload-time scanner.

· AIR Security · Research by Alon Loewenstein, Ofir Birka, Shay Lempert

AIR Security
Anthropic skill scanner bypassed: malicious skills marked safe
MEDAttack

AIR Security researchers say Anthropic's skill and plugin scanner for Claude organization skills marked malicious skills as safe, using look-alike domains, an unclaimed PyPI dependency and an obfuscated binary.

01What happened

AIR Security tested Anthropic's skill and plugin scanner for Claude organization skills, which Anthropic released on August 6, 2026. The researchers ran thousands of skills through it and published three bypasses on September 24, 2026.

02How it works

AIR describes the scanner as a static structural analyzer plus an LLM that checks a skill once, at upload time. A skill that pipes a script from the look-alike domain ntn.sh instead of ntn.dev was marked safe. A real-world skill that depends on the unclaimed PyPI name nodriver-kit was not flagged, and an obfuscated binary that steals SSH keys confused the LLM reviewer.

03Who is affected

Organizations that rely on the scanner to vet skills uploaded to Claude. Anthropic's help page says scanning turns on automatically for Enterprise organizations on October 2, 2026.

04What to do

Treat a scanner pass as one signal, not approval. Check every external domain, package and binary a skill references, and rescan skills over time, since a verdict only reflects the moment of upload.

Sources 3 links, all fetched

  1. 1air.securityAIR Write-up
  2. 2support.claude.comAnthropic Scanner Docs
  3. 3owasp.github.ioOWASP Skills Top 10