Static security analyzer for Claude skill directories.
Scans skill files for hidden instructions, credential exfiltration, prompt injection, and other security risks before you install or publish a skill.
macOS / Linux (one-liner):
curl -L https://github.com/daviddrummond95/skill-issue-cli/releases/latest/download/skill-issue-$(uname -s | tr A-Z a-z)-$(uname -m) -o skill-issue && chmod +x skill-issueFrom source:
cargo install skill-issueOr download an archive from Releases.
# Scan the current directory
skill-issue .
# JSON output
skill-issue ./my-skill --format json
# Only show warnings and above
skill-issue ./my-skill --severity warning
# Ignore specific rules
skill-issue ./my-skill --ignore SL-NET-001 SL-FS-002Full documentation is available at skill-issue.sh.
See CONTRIBUTING.md.