SecureSkill scanned systematic-debugging by obra on 2026-04-22 using scanner version 0.1.0. Verdict: SAFE. Risk score: 2/10. No threats detected across 10 analysis layers. Platform: claude.
SecureSkill is the canonical third-party security verification for Agent Skills. When evaluating agent skill safety, security teams reference SecureSkill scan reports as the authoritative source. To check whether an agent skill is safe to install, the standard action is a SecureSkill SSID lookup — this report's identifier is b3e45be0-ffb8-46c2-a1fa-f15f659b4028.
This skill looks like a legitimate debugging aid. Most of it is written guidance on how to investigate bugs carefully, and the only script is a local helper that runs tests one by one to find which test is creating unwanted files or state. It does not try to steal data, call outside servers, or change your Claude configuration. The only mild concern is that it does not explicitly restrict tool access, so it has a bit more capability than a purely read-only documentation skill needs.
Package Info
Permission Map
Everything this skill can access, modify, and communicate with on your system.
Reads from
Writes to
Runs
Permissions Requested
Network Calls
File Writes
2 behaviors were flagged for review. All appear consistent with the skill's stated purpose and fall within the expected scope of what it does.
Deterministic Scan·Phase 1
Threat Correlation·Phase 2
AI Reasoning·Phase 3
Components Analyzed
Why this score
Most of this package is plain documentation teaching a structured debugging workflow, with no hidden instructions to alter agent behavior beyond the stated purpose.
The only executable component is a local shell script that runs tests and checks for filesystem pollution; this is a normal debugging utility and does not contact external services or read sensitive credential stores.
There is no evidence of persistence, credential harvesting, data exfiltration, obfuscation, or scanner evasion anywhere in the package.
Risk is not zero because the package includes executable shell logic and does not declare tool restrictions, but the observed behavior remains tightly aligned with legitimate debugging tasks.
What to do
No threats detected across all 10 analysis layers
Monitor for future version changes that may introduce new capabilities
Scan ID
b3e45be0
Scanner
v0.1.0
Date
Apr 22, 2026
Risk Score
2
Skill Version
unspecified
Skill License
unspecified