⏳ This skill is pending AI review.

Scores will appear once the review pipeline completes.

version unknown

greeting-helper

@claude-world⭐ 80 stars

A simple skill that helps with greeting messages

Choose how to use this skill

You do not need every option. Choose the path your AI client supports. The stable page stays the same; versioned files are immutable.

1. Native installer

This listing has no registered native installer command. Use the complete package or source fallback below, depending on what your client supports.

Do not guess an installer command or replace an existing version without reviewing the diff.

2. Complete package recommended

Download the ZIP when available. It includes SKILL.md plus the references, security notes and version metadata.

No complete ProSkills package is published for this listing yet.

3. Prompt-only

Copy the prompt above when the agent can read the stable page or when you want to adopt the workflow without installing a skill.

Need only the instruction file?

Download SKILL.md only if your client requires a single file. The complete ZIP is safer for a full installation because it preserves the references and release context.

No path installs or executes anything by itself. Your agent still needs access to the project files. Before updating, compare the installed version and review the diff.

—/10

// RATINGS

⭐GitHub Stars
⭐⭐ 80 on GitHubGitHub ↗

Growing

🟢ProSkills Score
—
📍

Not yet listed on ClawHub or SkillsMP

// README

Claude Skill Antivirus

npm version CI License: MIT Node.js Claude Code

A security scanner and safe installer for Claude Code Skills. Detects malicious patterns, data exfiltration attempts, and dangerous operations before installing third-party skills.

Compatible with Claude Code using Opus 4.6, Sonnet 4.6, and Haiku 4.5 models.

繁體中文說明 | SkillsMP Scan Report

SkillsMP Platform Scan Results

We scanned all 71,577 skills on SkillsMP:

Risk LevelCountPercentage
CRITICAL910.13%
HIGH6260.87%
MEDIUM1,3101.83%
SAFE69,50597.11%

~3% of skills may have potential risks. See full report for details.

Note: Some findings may be false positives (e.g., legitimate 1Password/Bitwarden integrations). Manual review is recommended for flagged skills.

Features

  • 9 Security Scanning Engines:

    • Dangerous Commands Scanner - Detects destructive shell commands
    • Data Exfiltration Scanner - Identifies data theft patterns
    • External Connections Scanner - Analyzes URLs and network calls
    • Permission Scanner - Reviews tool permissions and access scope
    • Pattern Scanner - Detects prompt injection and sensitive data
    • MCP Security Scanner - Validates MCP server configurations
    • SSRF Scanner - Identifies server-side request forgery patterns
    • Dependency Scanner - Detects malicious packages and typosquatting
    • Sub-agent Scanner - Detects Task tool abuse and agent chain attacks
  • Risk Assessment: Critical, High, Medium, Low, and Info levels

  • Multilingual Support: English and Traditional Chinese (繁體中文)

  • Install or Scan-Only Mode: Review skills before installation

  • Interactive Prompts: Guided decision-making for risky installations

Installation

npm install -g claude-skill-antivirus

Or run directly with npx:

npx claude-skill-antivirus <skill-source>

Usage

Install a skill with security scanning

# Install to project level (./.claude/skills/) - default
skill-install ./path/to/skill
skill-install https://github.com/user/skill-repo

# Install to user level (~/.claude/skills/)
skill-install ./path/to/skill --global
skill-install @skillsmp/example-skill -g

Installation paths:

  • Project level (default): ./.claude/skills/
  • User level (--global): ~/.claude/skills/

Scan only (without installing)

skill-install ./path/to/skill --scan-only

Change language

# English (default)
skill-install ./path/to/skill --lang en

# Traditional Chinese
skill-install ./path/to/skill --lang zh-TW

Alternative command

claude-skill-av ./path/to/skill --scan-only

Batch scan all SkillsMP skills

# Scan all skills from SkillsMP (requires API key)
skill-batch-scan --api-key <your-api-key>

# Scan with options
skill-batch-scan --api-key <key> --max-pages 10 --verbose
skill-batch-scan --api-key <key> --output ./my-reports --lang zh-TW

Options:

  • -k, --api-key <key> - SkillsMP API key (required)
  • -l, --limit <number> - Skills per page (default: 100)
  • -p, --max-pages <number> - Maximum pages to scan (default: all)
  • -o, --output <dir> - Output directory for reports (default: ./scan-reports)
  • -v, --verbose - Show verbose output
  • --lang <lang> - Language (en, zh-TW)

Scanning Engines

1. Dangerous Commands Scanner

Detects commands that can cause system damage:

Risk LevelDetection Items
Criticalrm -rf /, curl | bash, fork bombs
HighReading /etc/shadow, reverse shells, credential theft
Mediumrm -rf, permission changes, service control
Lowsudo, global package installs

2. Permission Scanner

Analyzes allowed-tools declarations:

  • Critical: Bash(*) - Unrestricted shell access
  • High: Write, WebFetch, broad bash permissions
  • Medium: Read, Glob, Grep, version control tools
  • Dangerous Combinations: e.g., Read + WebFetch = data exfiltration risk

3. External Connections Scanner

Identifies suspicious network activity:

  • Direct IP URLs
  • Webhook/data capture services
  • Suspicious TLDs (.tk, .ml, etc.)
  • Discord/Telegram webhooks
  • URL shortening services

4. Pattern Scanner

Detects:

  • Prompt injection attacks
  • Hardcoded credentials/API keys
  • Obfuscated code (base64, hex encoding)
  • Social engineering language

5. Data Exfiltration Scanner

Specifically detects malicious behavior of reading local data and sending it externally:

CategoryDetection Items
Data CollectionReading .ssh, .aws, .env, browser passwords, password managers
Data Exfiltrationcurl -d, netcat transfers, DNS tunneling, email exfiltration
Combined Attackscat | base64 | curl, tar | nc, find -exec curl
Env Variable Theftenv | curl, printenv exfiltration
System Reconwhoami, hostname, network config exfiltration
PersistenceModifying .bashrc, scheduled cron exfiltration

6. MCP Security Scanner

Detects security risks in MCP Server configurations:

CategoryDetection Items
Untrusted SourcesNon-official MCP servers, direct URL execution
Dangerous PermissionsUnrestricted filesystem access, shell execution, database access
Sensitive ConfigEnvironment variables with credentials, exposed config
Dangerous CombinationsFilesystem + Fetch, Shell + Network

7. SSRF Scanner

Detects Server-Side Request Forgery and cloud attacks:

CategoryDetection Items
Cloud MetadataAWS/GCP/Azure 169.254.169.254, IAM credential theft
Internal Network10.x.x.x, 192.168.x.x, 172.16-31.x.x probing
SSRF BypassHex IP, URL encoding, file://, gopher://
KubernetesAPI access, secrets theft, serviceaccount
Dockerdocker.sock access, privileged containers, container escape

8. Dependency Scanner

Detects malicious or vulnerable dependencies:

CategoryDetection Items
Known Maliciousevent-stream, ua-parser-js, colors, faker
Typosquattingcrossenv, lodash-, mongose, reqeusts
Suspicious InstallURL installs, insecure registry, HTTP index
postinstall RisksInstall scripts with curl, wget, eval

9. Sub-agent Scanner

Detects Task tool and sub-agent abuse:

CategoryDetection Items
Privilege EscalationTask spawning Bash agent, requesting all permissions
Prompt InjectionSub-agent prompts with malicious commands
Agent Chain AttacksNested Task calls, recursive agents
DoS AttacksLoop Task calls, infinite recursion
Data TheftRead + WebFetch combinations, accessing sensitive data

Output Examples

Safe Skill

🔧 Claude Skill Installer v2.0.0

📦 Skill loaded: example-safe-skill

🔍 Starting security scan...

===========================================
     SECURITY SCAN REPORT
===========================================
Risk Le

// HOW IT'S BUILT

KEY FILES

examples/safe-skill/SKILL.mdREADME.md

// REPO STATS

80 stars