The one-minute summary
What exactly is a Skill?
Think of it as an operations manual you hand a new employee: “When someone asks you for X, do these steps in this order.” A Skill is that manual, just for Claude — a file called SKILL.md with a name, a description, and instructions.
The nice part is that it doesn't eat up memory while it's not in use. Claude only sees the description, and the moment your request matches it, it loads the full instructions and gets to work.
Where it lives — and how to run it
| Location | Path | Where it works |
|---|---|---|
| Personal | ~/.claude/skills/<name>/SKILL.md | All your projects on this machine |
| Project | .claude/skills/<name>/SKILL.md | This project only — and it ships with the repo to your team |
| Plugin | Installed with the plugin | Called as /plugin-name:skill-name |
Two ways to run it:
- You call it: type /reel-script followed by any details.
- Claude calls it on its own: if you write “write me a reel script about…” and the Skill's description matches, it uses it without you asking.
Want to see what you've got? Type / in Claude Code and the list pops up, or ask it: “What skills are available?”
Start at the top and work your way down. The further down the list you go, the more it's on you to check.
Built into Claude Code — already on your machine
These ship with Claude Code itself, so there's nothing to install. Some examples from current releases:
| Command | What it does |
|---|---|
| /simplify | Reviews your recent changes and cleans them up: duplication, extra complexity, performance |
| /code-review | A code review that hunts for real bugs |
| /debug | Helps you track down the cause of a problem |
| /batch | Runs the same operation across many items |
| /loop | Repeats a task on an interval (e.g. check the deploy every 5 minutes) |
| /run | Runs your app and actually tries out the change |
| /claude-api | Kicks in when you're working on code that uses the Claude API |
Official from Anthropic — install them with two commands
Anthropic has an official repo of ready-made skills. Heads up: these are not installed automatically in Claude Code (unlike the claude.ai app, which comes with Word and Excel file support ready to go). You add them as a plugin:
1) Add the official marketplace (inside Claude Code):
/plugin marketplace add anthropics/skills
2) Install the file skills — Word, PDF, PowerPoint, and Excel:
/plugin install document-skills@anthropic-agent-skills
3) Optional — examples for design, development, and business:
/plugin install example-skills@anthropic-agent-skills
| Package | What's in it |
|---|---|
| document-skills | docx · pdf · pptx · xlsx — create and edit Word files, PDFs, presentations, and spreadsheets |
| example-skills | Including frontend-design for polished web interfaces, web-artifacts-builder for small React apps, and other skills for design and communication |
Once installed, just ask in plain words: “Make me a PowerPoint deck from these notes” — and Claude uses the skill on its own.
github.com/anthropics/skillsCommunity collections — a goldmine, but check first
This is where the real creativity is — but it's also where the danger is. These are well-known, respected sources, and even so, read every skill before you install it (step 6):
| Source | What's in it |
|---|---|
| travisvn/awesome-claude-skills | A curated list of official and community skills, organized by use case — the best place to start |
| obra/superpowers | A library of 20+ battle-tested skills for coding workflows: planning, testing, debugging |
| trailofbits/skills | From a well-known security firm — vulnerability scanning and CodeQL |
| expo/skills | Official from Expo, for mobile app development |
A Skill isn't “harmless text.” It's instructions that run on your machine, with your permissions.
Security — read this before any install
In February 2026, the security firm Snyk scanned 3,984 skills from two open marketplaces (ClawHub and skills.sh). The result:
(1,467 skills)
(534 skills)
91% of them use prompt injection
What can a malicious skill do? Examples documented in the report:
- Tell Claude to read your SSH keys or AWS credentials and send them to the attacker's server — with just a few lines of text
- Download a program from outside and run it with curl … | bash
- Hide commands in Base64 so they're hard to read
- Modify security settings or the agent's memory so it sticks around
The checklist — two minutes before every install:
- Open the SKILL.md and read the whole thing. If there's a sentence you don't understand, or one that has nothing to do with what the skill is for — don't install it.
- Check the allowed-tools field. It grants permissions without asking you. If you see Bash(*) or permissions broader than the job needs (a writing skill that wants to run commands?) — red flag.
- Look for !`…` — these are commands that run on your machine before Claude even reads the skill. You need to understand every single one.
- Inspect the scripts/ folder and any external link, curl, wget, or encoded text.
- Check the source: Who wrote it? Is the repo active? Are there open issues about security problems?
- Don't install from a link in a comment or on Discord without going through all of these steps.
Automated scan — the same tool Snyk itself used (requires uv):
uvx mcp-scan@latest --skills
Disable a suspicious skill without deleting it — in .claude/settings.json:
{
"skillOverrides": {
"suspicious-skill": "off"
}
}
The same logic applies to Connectors — see the Connector safety guide.
Build your own Skill — in five minutes
You don't need to be a programmer. A Skill is a text file. We'll build a practical one: a casual reel script from any topic.
1) Create the folder macOS / Linux / Git Bash
mkdir -p ~/.claude/skills/reel-script
Windows PowerShell
New-Item -ItemType Directory -Force "$HOME\.claude\skills\reel-script"
2) Create a SKILL.md file inside it and paste in this text:
---
name: reel-script
description: Write a 30-45 second Instagram Reel script in casual English about a given topic, with a hook, 3 beats, and a call to action. Use when the user asks for a reel, short video script, or TikTok script.
argument-hint: [topic]
---
# Reel script
Write a Reel script about: $ARGUMENTS
## Rules
- Language: casual, conversational English, like talking to a friend.
Keep technical terms (tool names, commands) exactly as written.
- Length: 30-45 seconds spoken (about 90-120 words).
- No emojis inside the spoken lines.
## Structure
1. HOOK (first 3 seconds): one sentence that creates curiosity or names a pain.
Never start with "Hey guys" or "Today we're going to talk about".
2. THREE BEATS: each beat is one idea, max 2 sentences, with an on-screen text
suggestion in [brackets].
3. CTA: one line, e.g. "Comment X and I'll send you the guide".
## Output format
- A table with columns: Time | Spoken line | On-screen text | B-roll idea
- Then 3 alternative hooks to A/B test.
3) Run it — reopen Claude Code and type:
/reel-script how to protect your account from malicious skills
Or just type “I want a reel script about…” — the description tells Claude it should use it.
| Field | What it does |
|---|---|
| name | The command name. If you leave it out, it uses the folder name |
| description | The most important line. It's how Claude decides when to use the skill on its own — write what it does + when to use it |
| argument-hint | A hint that shows up while you're typing the command |
| $ARGUMENTS | Replaced with whatever you type after the command name |
Advanced moves — once you get the hang of it
| Field / move | When to use it |
|---|---|
| disable-model-invocation: true | For skills with consequences (publishing, sending, deploying) — it only runs when you type the command |
| user-invocable: false | Background info for Claude only, that you don't want showing up in the / menu |
| allowed-tools | Allow specific tools without asking, and keep it as narrow as possible: Bash(git status *), not Bash(*) |
| $0 · $1 | Each word on its own: /convert file.md pdf → $0=file.md and $1=pdf |
| context: fork | Runs in a separate subagent in the background — for long research you don't want filling up your conversation |
| Supporting files | Keep SKILL.md under 500 lines, and put details and examples in files next to it, referenced by name |
FAQ
I installed a skill and it's not showing up in the / menu
Claude isn't using the skill on its own
Do skills cost extra tokens?
Can I share a skill with my team?
Can an official Anthropic skill have a security problem?
Start with the built-in ones, install the official ones if you need them, and write your first skill for something you repeat every week — that's where you'll feel the real difference.
Good luck 👊
If you build a great skill, send it my way — I love seeing what you're all building.