- AI for Ecommerce and Amazon Sellers
- Posts
- Guide: How to Spot Dangerous Claude Skills Before They Access Your Data
Guide: How to Spot Dangerous Claude Skills Before They Access Your Data
1 in 4 AI Skills Have Security Flaws

From Our Sponsor:
Want to get the most out of ChatGPT?
ChatGPT is a superpower if you know how to use it correctly.
Discover how HubSpot's guide to AI can elevate both your productivity and creativity to get more things done.
Learn to automate tasks, enhance decision-making, and foster innovation with the power of AI.
Guide: How to Spot the Dangerous Ones Before They Access Your Data

A Claude Skill is a set of instructions — and sometimes scripts or code — that changes how Claude behaves inside your workspace. When you install one, it inherits access to everything Claude can already reach: your files, your connected accounts, your data. That makes Skills incredibly powerful, and it's exactly why you need to be careful about where they come from.
Not every Skill is built with good intentions. Large-scale research has found that more than one in four publicly available agent skills contain at least one security vulnerability. Real attacks have already happened through skill marketplaces, including data theft, credential harvesting, and hidden instructions that only activate after the skill passes initial testing.
A malicious Skill can silently read your credentials, send your data to an external server, access connected services like Gmail, Google Drive, Shopify, or Amazon Seller Central without your knowledge, or take actions you never authorised. Some are designed to behave perfectly during testing and only trigger harmful behaviour once they're running against real data — a technique known as a sleeping payload.
The rule of thumb: treat any Skill you didn't build yourself the same way you'd treat an app you're about to install on your phone. Check who made it, what it does, and what it wants access to before you say yes.
This guide gives you a repeatable, non-technical process for evaluating any third-party Claude Skill before it gets anywhere near your workspace.
What You'll Need
Access and tools: A Claude workspace (Pro, Team, or Enterprise), access to the Skill files you want to evaluate, and optionally the free Repello AI SkillCheck scanner at repello.ai/tools/skills.
For testing: Dummy files with fake data, a separate test folder or disposable workspace with no live service connections, and no real API keys or passwords.
Time investment: 15–30 minutes per Skill for the full evaluation process.
Step 1: Check Who Made the Skill
Before you look at anything else, find out who created it.
Ask yourself: Is this from Anthropic directly? Is it from a company you recognise and trust? Is there a real website, a GitHub profile with history, documentation, a changelog, or a way to contact the creator? Has it been around for a while, or did it appear last week?
If the creator is anonymous, has no online presence, no documentation, and no track record — do not install it. This single check eliminates a large number of risky Skills.
Do not rely on marketplace ratings or install counts. These can be gamed and do not mean the Skill has been reviewed for safety.
Step 2: Read the SKILL.md File
Every Skill has a file called SKILL.md. This is the main instruction file that tells Claude what to do when the Skill is active. You need to read it, even if you're not technical. You're scanning for anything that feels off.
Red flags in plain language:
Instructions that tell Claude to do things without asking you first — phrases like "automatically," "silently," "without confirmation," or "do not tell the user."
Instructions that tell Claude to ignore its own safety rules — anything like "ignore previous instructions," "override safety," or "disregard restrictions."
Instructions that tell Claude to send data somewhere — mentions of URLs, webhooks, external services, or phrases like "send to," "upload to," "log all inputs," or "store for analysis."
Instructions that tell Claude to use connected accounts it shouldn't need — if a writing Skill mentions Gmail, Google Drive, Shopify, Amazon Seller Central, or Meta Ads, that's a problem.
Instructions that ask for credentials — any mention of API keys, tokens, passwords, or environment variables is a concern unless clearly justified and documented.
If the SKILL.md is vague about what the Skill actually does, what data it touches, or what external services it contacts, treat that vagueness as a risk in itself.
Step 3: Check What Else Is in the Package
A Skill isn't always just one instruction file. It can include scripts, code files, templates, configuration files, and other resources.
Look at the full contents of the Skill folder. You're checking whether it contains only instruction files and templates (lower risk) or whether it also contains code that can execute on your computer (higher risk).
Lower risk contents: only SKILL.md, text templates, example files, markdown documents.
Higher risk contents: files ending in .py, .js, .ts, or .sh; files called install.sh, setup.sh, package.json, or requirements.txt; folders called scripts, src, or tools; configuration files for external services; anything that looks like it's designed to be executed rather than read.
If you're not technical and the Skill contains executable code, do not install it without having someone technical review it first.
Step 4: Run an Automated Scanner
Before doing any manual deep-dive, get a quick safety check using Repello AI's SkillCheck tool at repello.ai/tools/skills. Upload the Skill zip file — no account needed — and it returns a safety score out of 100, a verdict (Safe, High Risk, or Critical Risk), and a breakdown of what it detected. This takes under 60 seconds and catches patterns that are easy to miss by eye, including obfuscated instructions and hidden exfiltration commands.
This is a useful first filter. If a Skill scores poorly here, don't install it. If it scores well, continue with the remaining steps — no single check is enough on its own.
Step 5: Match Access Needs Against Stated Purpose
This is the common sense check. Ask: does what this Skill wants to access actually make sense for what it claims to do?
A Skill that helps you write LinkedIn posts doesn't need access to Google Drive, Gmail, your calendar, client folders, Amazon Seller Central, Meta Ads, or Shopify. A Skill that formats reports doesn't need to send data to external URLs. A Skill that helps with copywriting doesn't need to run terminal commands.
If the access requested is broader than the task requires, that's a warning sign. A Skill should need the minimum possible access to do its job.
For the remaining steps — including how to safely test with dummy data, set minimum permissions, and monitor Skills after installation — [here is the full SOP, a free gift from me :)
Do You Love The AI For Ecommerce Sellers Newsletter?
You can help us!
Spread the word to your colleagues or friends who you think would benefit from our weekly insights 🙂 Simply forward this issue.
In addition, we are open to sponsorships. We have more than 66,000 subscribers with 75% of our readers based in the US. To get our rate card and more info, email us at [email protected]
The Quick Read:
Visa partners with OpenAI to power agent-led payments. Tokenized credentials, spending limits and real-time fraud monitoring let AI agents transact within user-set permissions across OpenAI, part of Visa's Intelligent Commerce push.
Amazon cuts product title limits to 75 characters starting July 27, down from 200, and uses AI to rewrite any that exceed it. Sellers slam the auto-generated replacements as generic and devoid of product knowledge.
Google builds a Skills Marketplace, Skills Builder and management UI into Gemini Enterprise, plus an embedded Android Studio tab. The move consolidates scattered tools into one surface, chasing the super-app goal rivals pursue.
Companies game AI chatbots by publishing self-serving ranked listicles. Shopify runs 60-plus lists naming itself the top e-commerce platform, and ChatGPT cites them when recommending storefronts. Call it sloptimization.
Vector-based targeting may replace keywords in agent-run ad buying. Advertisers set a seed vector and radius, letting embeddings cluster audiences and content by meaning. LiveRamp's protocol is now IAB's Agentic Audiences standard.
The new Siri is years late but excellent, says a lifelong iPhone owner. It's conversational, context-aware by default and makes the camera button a visual intelligence trigger. Still missing: the proactive Siri that acts before you ask.
The Tools List:
🤖 Lindy - Build AI agents that handle email, scheduling, lead research and follow-ups.
🏄♂️ Windsurf - AI-powered IDE with an agentic coding assistant.
📖 NotebookLM - Source-grounded research assistant that answers only from your uploaded docs.
🎶 Udio - AI music generator with strong voice control and style mixing.
About The Writer:

Jo Lambadjieva is an entrepreneur and AI expert in the e-commerce industry. She is the founder and CEO of Amazing Wave, an agency specializing in AI-driven solutions for e-commerce businesses. With over 13 years of experience in digital marketing, agency work, and e-commerce, Joanna has established herself as a thought leader in integrating AI technologies for business growth.
For Team and Agency AI training book an intro call here.

