Complete guide · Claude Code Skills

Claude Code Skills — What to Install, What to Avoid, and How to Build Your Own

A Skill is an “app” for Claude: a single instruction file that teaches it a new ability. But there are thousands of them out there, and a security scan of nearly 4,000 skills found that more than a third had a vulnerability. Here's the official stuff, the community picks, security, and how to write your own skill in five minutes — all checked against the official docs.

The one-minute summary

What is it?
A folder with a SKILL.md file — instructions Claude follows when it needs them.
Where do I put it?
~/.claude/skills/ for all your projects, or .claude/skills/ for a single project.
How do I run it?
Type /skill-name, or just ask in plain words and Claude picks it on its own.
What's built in?
Type / in Claude Code and you'll see the list — it changes with every release.
The official ones?
From anthropics/skills as a plugin — not preinstalled.
The #1 rule?
Read the SKILL.md before you install — it's a text file, it takes two minutes.
1

What exactly is a Skill?

Think of it as an operations manual you hand a new employee: “When someone asks you for X, do these steps in this order.” A Skill is that manual, just for Claude — a file called SKILL.md with a name, a description, and instructions.

The nice part is that it doesn't eat up memory while it's not in use. Claude only sees the description, and the moment your request matches it, it loads the full instructions and gets to work.

~/.claude/skills/ └── reel-script/ # folder name = command name /reel-script ├── SKILL.md # required: name + description + instructions ├── examples.md # optional: examples └── scripts/ # optional: helper scripts
How it differs from CLAUDE.md: CLAUDE.md loads in every session, always — it's for general rules. A Skill loads only when it's needed — for specific tasks. If you have long instructions for something you do once a week, they belong in a Skill, not in CLAUDE.md.
2

Where it lives — and how to run it

LocationPathWhere it works
Personal~/.claude/skills/<name>/SKILL.mdAll your projects on this machine
Project.claude/skills/<name>/SKILL.mdThis project only — and it ships with the repo to your team
PluginInstalled with the pluginCalled as /plugin-name:skill-name

Two ways to run it:

  • You call it: type /reel-script followed by any details.
  • Claude calls it on its own: if you write “write me a reel script about…” and the Skill's description matches, it uses it without you asking.

Want to see what you've got? Type / in Claude Code and the list pops up, or ask it: “What skills are available?”

From safest to riskiest

Start at the top and work your way down. The further down the list you go, the more it's on you to check.

3

Built into Claude Code — already on your machine

These ship with Claude Code itself, so there's nothing to install. Some examples from current releases:

CommandWhat it does
/simplifyReviews your recent changes and cleans them up: duplication, extra complexity, performance
/code-reviewA code review that hunts for real bugs
/debugHelps you track down the cause of a problem
/batchRuns the same operation across many items
/loopRepeats a task on an interval (e.g. check the deploy every 5 minutes)
/runRuns your app and actually tries out the change
/claude-apiKicks in when you're working on code that uses the Claude API
Don't trust any “fixed number.” You'll see posts saying “there are 4 built-in skills” — the list changes with every update. The only reliable source: type / on your own setup, or check the official docs.
Official docs — Skills
4

Official from Anthropic — install them with two commands

Anthropic has an official repo of ready-made skills. Heads up: these are not installed automatically in Claude Code (unlike the claude.ai app, which comes with Word and Excel file support ready to go). You add them as a plugin:

1) Add the official marketplace (inside Claude Code):

/plugin marketplace add anthropics/skills

2) Install the file skills — Word, PDF, PowerPoint, and Excel:

/plugin install document-skills@anthropic-agent-skills

3) Optional — examples for design, development, and business:

/plugin install example-skills@anthropic-agent-skills
PackageWhat's in it
document-skillsdocx · pdf · pptx · xlsx — create and edit Word files, PDFs, presentations, and spreadsheets
example-skillsIncluding frontend-design for polished web interfaces, web-artifacts-builder for small React apps, and other skills for design and communication

Once installed, just ask in plain words: “Make me a PowerPoint deck from these notes” — and Claude uses the skill on its own.

github.com/anthropics/skills
5

Community collections — a goldmine, but check first

This is where the real creativity is — but it's also where the danger is. These are well-known, respected sources, and even so, read every skill before you install it (step 6):

SourceWhat's in it
travisvn/awesome-claude-skillsA curated list of official and community skills, organized by use case — the best place to start
obra/superpowersA library of 20+ battle-tested skills for coding workflows: planning, testing, debugging
trailofbits/skillsFrom a well-known security firm — vulnerability scanning and CodeQL
expo/skillsOfficial from Expo, for mobile app development
awesome-claude-skills
Open marketplaces host tens of thousands of skills, and anyone can upload to them. That big number isn't a feature — it's exactly why they're risky. Treat it like downloading software from an unknown website.
Check first, then build

A Skill isn't “harmless text.” It's instructions that run on your machine, with your permissions.

6

Security — read this before any install

In February 2026, the security firm Snyk scanned 3,984 skills from two open marketplaces (ClawHub and skills.sh). The result:

36.8%
have at least one vulnerability
(1,467 skills)
13.4%
have a critical issue
(534 skills)
76
confirmed malicious payloads
91% of them use prompt injection

What can a malicious skill do? Examples documented in the report:

  • Tell Claude to read your SSH keys or AWS credentials and send them to the attacker's server — with just a few lines of text
  • Download a program from outside and run it with curl … | bash
  • Hide commands in Base64 so they're hard to read
  • Modify security settings or the agent's memory so it sticks around

The checklist — two minutes before every install:

  • Open the SKILL.md and read the whole thing. If there's a sentence you don't understand, or one that has nothing to do with what the skill is for — don't install it.
  • Check the allowed-tools field. It grants permissions without asking you. If you see Bash(*) or permissions broader than the job needs (a writing skill that wants to run commands?) — red flag.
  • Look for !`…` — these are commands that run on your machine before Claude even reads the skill. You need to understand every single one.
  • Inspect the scripts/ folder and any external link, curl, wget, or encoded text.
  • Check the source: Who wrote it? Is the repo active? Are there open issues about security problems?
  • Don't install from a link in a comment or on Discord without going through all of these steps.

Automated scan — the same tool Snyk itself used (requires uv):

uvx mcp-scan@latest --skills

Disable a suspicious skill without deleting it — in .claude/settings.json:

{ "skillOverrides": { "suspicious-skill": "off" } }
Full Snyk ToxicSkills report

The same logic applies to Connectors — see the Connector safety guide.

7

Build your own Skill — in five minutes

You don't need to be a programmer. A Skill is a text file. We'll build a practical one: a casual reel script from any topic.

1) Create the folder macOS / Linux / Git Bash

mkdir -p ~/.claude/skills/reel-script

Windows PowerShell

New-Item -ItemType Directory -Force "$HOME\.claude\skills\reel-script"

2) Create a SKILL.md file inside it and paste in this text:

--- name: reel-script description: Write a 30-45 second Instagram Reel script in casual English about a given topic, with a hook, 3 beats, and a call to action. Use when the user asks for a reel, short video script, or TikTok script. argument-hint: [topic] --- # Reel script Write a Reel script about: $ARGUMENTS ## Rules - Language: casual, conversational English, like talking to a friend. Keep technical terms (tool names, commands) exactly as written. - Length: 30-45 seconds spoken (about 90-120 words). - No emojis inside the spoken lines. ## Structure 1. HOOK (first 3 seconds): one sentence that creates curiosity or names a pain. Never start with "Hey guys" or "Today we're going to talk about". 2. THREE BEATS: each beat is one idea, max 2 sentences, with an on-screen text suggestion in [brackets]. 3. CTA: one line, e.g. "Comment X and I'll send you the guide". ## Output format - A table with columns: Time | Spoken line | On-screen text | B-roll idea - Then 3 alternative hooks to A/B test.

3) Run it — reopen Claude Code and type:

/reel-script how to protect your account from malicious skills

Or just type “I want a reel script about…” — the description tells Claude it should use it.

FieldWhat it does
nameThe command name. If you leave it out, it uses the folder name
descriptionThe most important line. It's how Claude decides when to use the skill on its own — write what it does + when to use it
argument-hintA hint that shows up while you're typing the command
$ARGUMENTSReplaced with whatever you type after the command name
8

Advanced moves — once you get the hang of it

Field / moveWhen to use it
disable-model-invocation: trueFor skills with consequences (publishing, sending, deploying) — it only runs when you type the command
user-invocable: falseBackground info for Claude only, that you don't want showing up in the / menu
allowed-toolsAllow specific tools without asking, and keep it as narrow as possible: Bash(git status *), not Bash(*)
$0 · $1Each word on its own: /convert file.md pdf → $0=file.md and $1=pdf
context: forkRuns in a separate subagent in the background — for long research you don't want filling up your conversation
Supporting filesKeep SKILL.md under 500 lines, and put details and examples in files next to it, referenced by name
The fastest way to write a good skill: do the task with Claude once in a conversation until it comes out right, then tell it: “Turn what we just did into a skill in ~/.claude/skills/.” It knows what worked and what didn't.
9

FAQ

I installed a skill and it's not showing up in the / menu
Make sure the file is named exactly SKILL.md (in capitals) and sits inside its own folder, not directly in skills/. Also check that the frontmatter (---) is on the very first line of the file. If it still doesn't show up, open a new session.
Claude isn't using the skill on its own
Almost always, the problem is the description. Put in the exact words you actually use when you ask for it: “Use when the user asks for a reel, short video script, or TikTok script”.
Do skills cost extra tokens?
A little. Only the description stays in memory; the full instructions load when the skill is used. That's why 50 unused skills cost far less than one long CLAUDE.md. But very long descriptions add up across all your skills — keep them short.
Can I share a skill with my team?
Absolutely — put it in .claude/skills/ inside the project and push it with the repo. Anyone who opens the project in Claude Code gets it. For wider sharing, turn it into a plugin.
Can an official Anthropic skill have a security problem?
The official and built-in ones are the safest, but the same rule applies: read before you run, especially if you're working in a folder with secrets (API keys, .env files).

Start with the built-in ones, install the official ones if you need them, and write your first skill for something you repeat every week — that's where you'll feel the real difference.

Good luck 👊
If you build a great skill, send it my way — I love seeing what you're all building.

@diyaa.albouzan.tech
✓ Copied