scripts/ may run shell commands; references/ may fetch external URLs. Malicious skills can trick the model into unsafe actions. Listing is not a security audit.
Guides·Agent Skills
Agent Skill safety
Skills may include scripts and external refs—how to review before installing.
Risks
Before you install
• Read full SKILL.md and scripts/ • Prefer official repos, high stars, trusted ClawHub authors • Test in isolation or a clone first • Never embed secrets in skills