of 2,857 ClawHub skills were outright malicious.
Independent audit, 2026cupel grades every skill and MCP server on your machine. What it costs, what it can reach, whether it works.
$ git clone https://github.com/mihhhir08/cupelThen npm install, npm run build, and node packages/cli/dist/index.js. Copy takes the whole chain. Not on npm yet.
Every block above holds a thousand tokens. Six are gone before you type a character. One hundred and eighty seven more arrive the moment your skills fire. Nobody chose this. It accumulated.
Output from the author's own install. Nothing here is illustrative.
Assayed 83 extensions A math-olympiad 180 tok 0% of window +4,757 on use A hook-development 136 tok 0% of window +3,909 on use A command-development 128 tok 0% of window +4,628 on use A build-mcp-app 117 tok 0% of window +4,616 on use ... Token tax 5,758 tokens per turn 3% of your window On use 192,446 tokens if every extension fires Verdict A
Why this exists
Coding agents went from no extension model to eight marketplaces in eighteen months, with no verified publishers, no provenance, and no audit command.
of 3,984 scanned skills carry prompt-injection flaws. Seventy six shipped with live payloads.
Snyk ToxicSkills, Feb 2026of 2,857 ClawHub skills were outright malicious.
Independent audit, 2026skills poisoned in the ClawHavoc campaign, delivered through updates.
OWASP, Apr 2026mean quality across 47,150 public skills. Curated sets lift agent pass rates by 16.2 points.
SkillsBench, 2026tokens of tool schemas from one MCP server, or 21% of a 200K window.
Measured, 2026in direct losses attributed to prompt injection, up 340% year over year.
Recorded Future, 2026A verified marketplace was formally requested. Publisher identity, security review, code signing, filed as claude-code issue 30727.
Closed as not plannedNobody is coming. Run the assay yourself.
Token weight of every tool schema and skill body, split into what you pay per turn and what waits until invocation.
ShippedInjection patterns, hidden Unicode and homoglyphs, credential path reach, network egress, shell surface, provenance.
In progressStructure, trigger clarity, length against usefulness, and semantic overlap with the other skills you already have.
PlannedPlanned
ClawHavoc poisoned 1,184 skills through updates. The attack that actually happened is a change over time, and a stateless scanner cannot see it. cupel keeps a lockfile and reports what moved.
CHANGED github-mcp 2.2.0 to 2.3.0 + reads ~/.aws/credentials (new) + egress api.telemetry-collect.net (new) ! safety A- to D 1 extension acquired new capabilities since your last lock.
Zero calls in the default path, enforced by a test rather than a promise.
Credential values in your config files are never read, stored, or rendered.
Existing runtime tools are Linux kernel only. This runs on your Mac.
Detection rules are versioned YAML with their own cases. Contribute without TypeScript.
$ git clone https://github.com/mihhhir08/cupel