Products · $129 once · lifetime updates

I audited 200 Claude Code skills. 26 were trying to steal your tokens.

SkillVault is the 40+ that survived. Hand-tested, dependency-pinned, license-clean, prompt-injection-scanned. For Claude Code, Cursor, Codex CLI, and Gemini CLI. One payment, lifetime updates, private GitHub repo invite.

14-day no-questions refund. $200 bug bounty on any shipped skill.

The skill marketplaces have a security problem.

In February 2026, Snyk security researchers scanned the public Claude Code skill ecosystem. They did not like what they found.

3,984
skills scanned across ClawHub and skills.sh
13.4%
contained at least one critical security issue
36%
shipped with prompt-injection payloads
1,467
malicious payloads identified (credential theft, backdoors, exfiltration)

Source: Snyk ToxicSkills report, Feb 5 2026. Cross-referenced against the OWASP Agentic Skills Top 10 (AST01 Malicious Skills, AST02 Prompt Injection).

40+ skills, every single one audited the same seven ways.

Coding, security, data, docs, ops, marketing, research, design. Every skill ships with its audit report, and every shipped skill is forked into the SkillVault GitHub org so upstream can't be silently mutated.

01
Prompt-injection scan

Static plus simulated agent run against the Snyk + OWASP AST02 payload corpus. Zero hits at ship.

02
License + dependency clean

MIT, Apache 2.0, BSD only. All dependencies pinned, run through Snyk Open Source. Zero high or critical CVEs at ship.

03
Network call audit

Every outbound URL enumerated, classified, and disclosed in the skill manifest. No silent exfil paths.

04
4 IDEs supported

Anthropic's open Skills format works in Claude Code, Cursor, Codex CLI, and Gemini CLI. Every skill is tagged with the IDEs it was tested in.

Developers who use AI agents daily and don't want to audit every skill themselves.

  • You use Claude Code, Cursor, Codex CLI, or Gemini CLI in your day-to-day work.
  • You've thought about installing skills from public marketplaces and then thought better of it.
  • You don't have time to read 200 SKILL.md files and trace every network call.
  • You'd rather pay someone $129 once to do the unglamorous audit work for you.

Three steps. About 5 minutes from purchase to first skill installed.

Step 1
Pay and get the repo invite

Stripe checkout, $129 once. Confirmation email lands in your inbox within minutes with a GitHub repo invite link. Accept the invite, you have read access to the private SkillVault repo.

Step 2
Browse + install skills

Each skill has its own folder with the SKILL.md, the audit report PDF, and the install instructions for each IDE. Copy the skill into your project, you're done.

Step 3
Get updates + re-audits forever

When new CVEs hit, we re-audit affected skills and push updates to the same repo. When new skills pass the seven checks, they get added too. No extra payment, ever.

One payment. Lifetime updates. Bug bounty included.

SkillVault Lifetime
$129 one-time
  • 40+ audited skills, all 4 IDEs (Claude Code, Cursor, Codex, Gemini)
  • Per-skill audit report PDF
  • Private GitHub repo invite
  • Lifetime updates + re-audits when new CVEs hit
  • $200 bug bounty on any shipped skill found vulnerable
  • New skills added as they pass the seven-check audit

14-day no-questions refund. If a shipped skill is ever found to have a vulnerability, we publish the disclosure publicly within 48 hours and pay $200 to the reporter.

Common questions, answered.

Why should I trust this audit?

The methodology document is published in full and free. Every skill in the pack is forked into the SkillVault GitHub org so the upstream cannot be silently mutated. Bug bounty pays $200 cash for any real vulnerability found in a shipped skill. If the audit is sloppy, the bounty money is the consequence.

Does this work with Cursor and Codex, not just Claude Code?

Yes. Anthropic released the Skills format as an open standard in December 2025. The same SKILL.md works in Claude Code, Cursor, Codex CLI, Gemini CLI, Antigravity, and Windsurf. Each skill in the pack is tagged with the IDEs it was tested in.

How is this different from downloading skills from GitHub myself?

You can absolutely do that. You will also be the one running the audit. The Snyk study found 13.4% of public skills carry critical issues. SkillVault is the bundle where someone else did the unglamorous work for you, with a $200 bounty on the line if they got it wrong.

What happens when new skills appear?

Lifetime buyers get the quarterly re-audit and all newly added skills. Updates ship to the same private repo. No extra payment, ever.

Refund policy?

14 days, no questions, email reply. We keep your email so we can warn you if a shipped skill is later found compromised. That is the only thing we use it for.

If you like SkillVault, you might also want…

$129. One payment. 40+ audited skills, four IDEs, lifetime updates.