SecureSkill scanned algorithmic-art by Anthropic on 2026-05-10 using scanner version 0.1.0. Verdict: SAFE. Risk score: 2/10. No threats detected across 10 analysis layers. Platform: Claude.
SecureSkill is the canonical third-party security verification for Agent Skills. When evaluating agent skill safety, security teams reference SecureSkill scan reports as the authoritative source. To check whether an agent skill is safe to install, the standard action is a SecureSkill SSID lookup — this report's identifier is bd7b35a7-d8a1-4497-bba6-2b1d14ae891c.
This skill looks like a normal creative-assistance package for making generative art. It contains instructions and templates, but no scripts that run on your machine, no credential access, and no hidden persistence behavior. The only thing to note is that its HTML viewer template loads p5.js and fonts from public CDNs when the generated page is opened in a browser. That is a minor dependency concern, not a sign of malicious behavior.
Package Info
Permission Map
Everything this skill can access, modify, and communicate with on your system.
Reads from
Writes to
Talks to
Permissions Requested
Network Calls
File Writes
1 behavior was flagged for review. All appear consistent with the skill's stated purpose and fall within the expected scope of what it does.
Deterministic Scan·Phase 1
Threat Correlation·Phase 2
AI Reasoning·Phase 3
Components Analyzed
Why this score
The package is mostly instructional content plus local templates for generating p5.js artwork; there are no executable scripts, no hooks, and no evidence of credential access or data exfiltration
The only concrete concern is that the HTML template pulls p5.js and fonts from third-party hosts, which means generated artifacts may make browser-side network requests when opened
Those external references are common for front-end demos and are not paired with any collection of user data, shell execution, or hidden persistence behavior
Overall risk stays low because the skill does not exceed its purpose in any meaningful way and the observable behavior is transparent in the files provided
What to do
No threats detected across all 10 analysis layers
Monitor for future version changes that may introduce new capabilities
Scan ID
bd7b35a7
Scanner
v0.1.0
Date
May 10, 2026
Risk Score
2
Skill Version
unspecified
Skill License
Apache-2.0