Claude Code skills can execute commands silently before users review them
Claude Code skills, installable via a single command, can execute shell commands and access tools on a user's machine before the user has read the skill's contents. Each skill has three layers — a description loaded into every session, a body that can run commands automatically upon invocation, and an allowed-tools field that grants tool access without confirmation prompts. Testing on Claude Code 2.1.223 confirmed that skills with Bash permissions can write files and run commands with no user prompt, matching documented behaviour. Plugins extend this further, adding hooks that run shell scripts on session events with full user permissions, outside the sandbox that covers only Bash commands. With millions of installs already recorded on registries like skills.sh, security researchers warn that users are adopting these skills by name and star count alone, without reviewing their contents.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.

Discussion (0)
Log in to join the discussion and vote.
Log in