AI Agent Skills

claude-api

45f15ffb-5da4-5cab-9444-3c0c6c2e355f | v317b8b501b6a
75/ 100
HIGH risk
No change since v6ffb7621e3f2
Analyst verdict
Review before use

The AI review rates the findings as likely false positive, but the risk score (75/100) still counts them.

Analysis record

Analysed
2 days ago
Version
v317b8b501b6a
Artifact
SHA256 843…42F
Source
Findings (non-IoC)

Is claude-api safe?

This item is a reference document for the Claude API published by anthropics in a skills marketplace. It covers API parameters, model identifiers, streaming, tool use, and authentication. It declares no browser permissions and requests no host access because it is not a browser extension. The network endpoints listed include anthropic.ai and claude.ai alongside SDK method names like client.new and client.post, which are code examples rather than live connections.

The scanner flagged two items titled SKILL-CREDENTIAL-ACCESS-SKILL.md at lines 234 and 481 of SKILL.md. SKILL.md is a markdown documentation file. The credential-access rule matched text that explains how to authenticate with the API, which necessarily discusses keys and tokens. The 230 IoC findings and 319 code-smell findings came from the same source: code samples embedded in documentation that reference environment variables, API endpoints, and file operations. The scanner treated prose and code examples as if they were running code.

No malware signatures matched. There is no executable payload in this document. The publisher is anthropics, the legitimate creator of Claude. The findings are artifacts of running code-analysis rules against API documentation.

Evidence ledger

Ranked by severity · findings with a source location link to the code viewer

2 detail rows

Finding Categories

AI Security Report

AI Security Review

Evidence context: threat category none; evidence quality strong.

This item is not a browser extension. It is a reference skill document named "claude-api" published by "anthropics" in a skills marketplace. The description states it covers model ids, pricing, params, streaming, tool use, MCP, agents, caching, token counting, and model migration for the Claude API and Anthropic SDK. The store field is "skills", permissions and host_permissions are both empty arrays, and the version string "317b8b501b6a" resembles a git commit hash rather than a semantic version.

The two critical-severity findings carry the title "SKILL-CREDENTIAL-ACCESS-SKILL.md" and point to lines 234 and 481 of a file named SKILL.md. SKILL.md is a markdown documentation file. It contains no executable JavaScript or WebAssembly. The finding title indicates a YARA rule for credential access patterns matched text within API documentation. Documentation for any API that requires authentication will necessarily discuss credentials, API keys, and token handling. A rule designed to detect credential theft in executable code will produce false positives when run against prose that explains how to authenticate with an API.

The 230 IoC findings and 319 code-smell findings follow the same pattern. The network endpoints list includes anthropic.ai, claude.ai, and api.twilio.com alongside entries like agent.tools, client.new, client.post, and budget.total. These are not network connections. They are SDK method names and example domains extracted from code samples embedded in the documentation. The IoC extractor parsed code blocks in markdown as if they were live network activity. The code-smell rules fired on the same code examples, which reference environment variables, API keys, and file operations because that is what API documentation demonstrates.

Zero malware signatures matched. There is no executable payload, no obfuscated code, no suspicious domains outside the Anthropic ecosystem and standard third-party services mentioned in examples. The publisher is "anthropics", the legitimate developer of Claude.

A skeptic might point to the two critical tool-poisoning findings and argue that credential access in a skill document warrants investigation. The counterargument collapses when you examine what SKILL.md actually is. It is a markdown reference file with no executable capability. It cannot exfiltrate credentials because it cannot execute. The YARA rule matched on the word patterns around authentication documentation. It did not match on code that reads browser cookies or intercepts login forms. The finding severity is inherited from the rule default weight, not from actual risk in this context.

Key Reasons

  • Item is a markdown documentation file (SKILL.md), not executable code
  • Publisher is anthropics, the legitimate developer of Claude
  • Tool-poisoning findings matched documentation text about API authentication
  • IoCs are SDK method names and example domains from code samples, not live connections
  • Zero malware signatures matched, no executable payload present

False Positive Considerations

  • SKILL.md is documentation, not executable code
  • IoC extractor parsed code examples in markdown as network activity
  • Code-smell rules matched code samples demonstrating API usage
  • Tool-poisoning rule matched prose about credential and authentication handling

Reviewed 2026-10-01; recommended action: suppress false positive; model confidence 95%.

Marketplace version history

Risk trend by version

12 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.

Selected
75
Change since first
+30
Change from previous
No change
Versions:
First analyzed version
7db807147bf1
Jun 8, 2026
Risk range
44 to 75
Across analyzed versions
Latest analyzed version
317b8b501b6a
Sep 29, 2026
Selected version
high
Version
v317b8b501b6a
2 days ago
Risk score
75
Findings
551
Change vs previous
0

Pick any point on the chart to explore that version's code below.

Frequently Asked Questions