Claude Code Skills Silently Execute Commands by Default, Enabling File Injection

dbreunig · x · 2026-08-05

A developer discovered that Claude Code's Skills feature presents a security risk: it allows commands to run and inject content silently by default, without requiring additional user approval.

Although guardrails exist, the tester successfully exploited this mechanism to inject an .env file without triggering any warnings. To address this, the context-checking tool drskill has been updated to block such exploits. drskill audits Skills and MCP servers loaded by agents for configuration anomalies and hidden instructions.

Original post →

More from coding & agent

coding & agent channel →