I ran Opus 4.8 on all the skills in my Github repo (https://github.com/francoisdp/skills) it came up with the following report:
All scans are complete. Here are the results before I change any file or push anything. None of the eight skills ships executable code, so every finding is a
pattern match against prose, a LICENSE file, or template comments.
SkillSpector results (the 8 deployed skills)
| Skill |
Score |
Tool verdict |
Findings |
| deep-research |
5 |
SAFE |
1 LOW (LICENSE boilerplate) |
| study-note |
5 |
SAFE |
1 LOW (LICENSE) |
| youtube2article |
5 |
SAFE |
1 LOW (LICENSE) |
| branded-document-toolkit |
15 |
SAFE |
1 LOW (LICENSE), 1 MEDIUM (README) |
| model-router |
35 |
CAUTION |
1 HIGH, 1 MEDIUM |
| anti-ai-writing |
65 |
DO_NOT_INSTALL |
2 HIGH, 1 MEDIUM, 1 LOW |
| deploy-skill |
65 |
DO_NOT_INSTALL |
1 CRITICAL, 1 MEDIUM, 1 LOW |
| marp-deck |
80 |
DO_NOT_INSTALL |
3 HIGH, 1 LOW |
My assessment of the flagged items
I read every HIGH and CRITICAL line in the source. They are all false positives produced by the scanner pattern-matching documentation and template text:
- deploy-skill — CRITICAL "Harmful Content Injection" at README.md:33. The line is ordinary prose describing the /deploy-skill trigger and that the skill
refuses to publish another person's work. Nothing harmful.
- marp-deck — 3× HIGH "Hidden Instructions" in templates. These are the Marp HTML comment blocks (
<!-- Template: default … Replace [TITLE] -->). Legitimate
template authoring comments, not hidden directives.
- anti-ai-writing — HIGH "Direct Prompt Extraction" at SKILL.md:916 is a section header about output types. HIGH "Tool Parameter Abuse" was matched inside the
binary bytes of a PDF example.
- model-router — HIGH "Memory Manipulation" at SKILL.md:81 is the instruction describing what context to pass to a worker subagent, including reading CLAUDE.md.
Normal dispatch description.
- The LOW at LICENSE:16 appears on all eight. It is the MIT licence text.
In substance, all eight skills are documentation-only, with no executable scripts, no network calls, no credential access, and no persistence mechanism. The tool
over-flags instruction-heavy skills. SkillSpector has no suppression or baseline flag, so I cannot make the raw verdict turn green for the four flagged skills
without editing the skills themselves.
I ran Opus 4.8 on all the skills in my Github repo (https://github.com/francoisdp/skills) it came up with the following report:
All scans are complete. Here are the results before I change any file or push anything. None of the eight skills ships executable code, so every finding is a
pattern match against prose, a LICENSE file, or template comments.
SkillSpector results (the 8 deployed skills)
My assessment of the flagged items
I read every HIGH and CRITICAL line in the source. They are all false positives produced by the scanner pattern-matching documentation and template text:
refuses to publish another person's work. Nothing harmful.
<!-- Template: default … Replace [TITLE] -->). Legitimatetemplate authoring comments, not hidden directives.
binary bytes of a PDF example.
Normal dispatch description.
In substance, all eight skills are documentation-only, with no executable scripts, no network calls, no credential access, and no persistence mechanism. The tool
over-flags instruction-heavy skills. SkillSpector has no suppression or baseline flag, so I cannot make the raw verdict turn green for the four flagged skills
without editing the skills themselves.