‹ The Index

Skill Security Check

plugin

Security audit plugin that scans Claude Code skills, hooks, and MCP configurations for threats. Detects 37 attack patterns including prompt injection, data exfiltration, supply chain attacks (ToxicSkills/ClawHavoc), credential theft, reverse shells, backdoor persistence, API endpoint hijacking, Unicode homoglyph attacks, and context window poisoning. Includes runtime hooks for Bash command validation and MCP response inspection.

Works with: Claude Code, Cursor, Claude Desktop, Codex CLI, Gemini CLI, Cline, Windsurf, VS Code

Category: Security — see all ranked ›

Security audit

Not scanned yet. We audit npm-published capabilities for known advisories, install-time scripts and permission surface; this one has no npm package we can resolve, or has not reached the queue.

source ↗  ·  plugin:aliksir/claude-code-skill-security-check/skill-security-check

Already running this? npx tashan-cli doctor checks your whole config against the Index — how it works ›