Anthropic skill scanner bypassed: malicious skills marked safe
Three simple tricks got malicious Claude skills past Anthropic's upload-time scanner.
· AIR Security · Research by Alon Loewenstein, Ofir Birka, Shay Lempert

AIR Security researchers say Anthropic's skill and plugin scanner for Claude organization skills marked malicious skills as safe, using look-alike domains, an unclaimed PyPI dependency and an obfuscated binary.
01What happened
AIR Security tested Anthropic's skill and plugin scanner for Claude organization skills, which Anthropic released on August 6, 2026. The researchers ran thousands of skills through it and published three bypasses on September 24, 2026.
02How it works
AIR describes the scanner as a static structural analyzer plus an LLM that checks a skill once, at upload time. A skill that pipes a script from the look-alike domain ntn.sh instead of ntn.dev was marked safe. A real-world skill that depends on the unclaimed PyPI name nodriver-kit was not flagged, and an obfuscated binary that steals SSH keys confused the LLM reviewer.
03Who is affected
Organizations that rely on the scanner to vet skills uploaded to Claude. Anthropic's help page says scanning turns on automatically for Enterprise organizations on October 2, 2026.
04What to do
Treat a scanner pass as one signal, not approval. Check every external domain, package and binary a skill references, and rescan skills over time, since a verdict only reflects the moment of upload.
Sources 3 links, all fetched
- 1air.securityAIR Write-up
- 2support.claude.comAnthropic Scanner Docs
- 3owasp.github.ioOWASP Skills Top 10