<!-- llms-explorer concept facts · https://llms-explorer.com/tree/claude-code-skills/ · pack 2026-09-08 · ~2238 tokens -->

# Claude Code Skills

> Reference for the Claude Code skills ecosystem — anatomy, authoring, discovery, distribution, management, composition, and optimization. Backed by references/claude-code-skills-context.md.

Parent: [Prompting & Agent Skills](https://llms-explorer.com/tree/prompting-agent-skills/) · 9 facets · 30 facts · page: https://llms-explorer.com/tree/claude-code-skills/

## Claude Code Skills Expert

- Reference for the Claude Code skills ecosystem - anatomy, authoring, discovery, distribution, management, composition, and optimization. Backed by references/claude-code-skills-context.md. — [source](https://llms-explorer.com/sources/mdb-context-hub/claude-code-skills/#claude-code-skills-expert)

## When NOT to use

- Plugin packaging, hook configuration, or agent definitions → use claude-code-plugins — [source](https://llms-explorer.com/sources/mdb-context-hub/claude-code-skills/#when-not-to-use)
- Searching the prompts.chat registry to find and install an existing skill → use skill-lookup — [source](https://llms-explorer.com/sources/mdb-context-hub/claude-code-skills/#when-not-to-use)
- Creating a brand-new skill interactively from a description → use skill-creator — [source](https://llms-explorer.com/sources/mdb-context-hub/claude-code-skills/#when-not-to-use)
- Optimizing trigger accuracy, fixing over-triggering, or improving prose quality of an existing skill → use skill-optimizer — [source](https://llms-explorer.com/sources/mdb-context-hub/claude-code-skills/#when-not-to-use)

## Skill precedence (highest to lowest)

- Enterprise managed settings — [source](https://llms-explorer.com/sources/mdb-context-hub/claude-code-skills/#skill-precedence-highest-to-lowest)
- Personal (~/.claude/skills/) — [source](https://llms-explorer.com/sources/mdb-context-hub/claude-code-skills/#skill-precedence-highest-to-lowest)
- Project (.claude/skills/) — [source](https://llms-explorer.com/sources/mdb-context-hub/claude-code-skills/#skill-precedence-highest-to-lowest)
- Plugin (plugin-name:skill-name) — [source](https://llms-explorer.com/sources/mdb-context-hub/claude-code-skills/#skill-precedence-highest-to-lowest)

## Security checklist

- Run uvx mcp-scan@latest --skills before installing unknown skills — [source](https://llms-explorer.com/sources/mdb-context-hub/claude-code-skills/#security-checklist)
- 36.8% of scraped skills have security flaws (Snyk ToxicSkills, Feb 2026) — [source](https://llms-explorer.com/sources/mdb-context-hub/claude-code-skills/#security-checklist)
- 13.4% contain critical vulnerabilities; 76 confirmed malicious payloads found — [source](https://llms-explorer.com/sources/mdb-context-hub/claude-code-skills/#security-checklist)
- Prefer Anthropic Official or Agensi-vetted skills for production use — [source](https://llms-explorer.com/sources/mdb-context-hub/claude-code-skills/#security-checklist)

## Full reference

- For complete coverage of all frontmatter fields, token budget management, skillOverrides, CI/CD integration, and skill composition patterns, read references/claude-code-skills-context.md in this directory. — [source](https://llms-explorer.com/sources/mdb-context-hub/claude-code-skills/#full-reference)

## Where this helps

- Deciding where a new skill should live given Claude Code's precedence order — enterprise managed settings, then personal ~/.claude/skills/, then project .claude/skills/ — when the same skill name exists at multiple levels. — [source](https://llms-explorer.com/tree/claude-code-skills/) *(AI-suggested, synthesized from this pack's existing facts — not extracted from a source document.)*
- Auditing an unfamiliar or third-party skill for security risk before installing it, given how measurably risky the current skill ecosystem is. — [source](https://llms-explorer.com/tree/claude-code-skills/) *(AI-suggested, synthesized from this pack's existing facts — not extracted from a source document.)*
- Distinguishing this reference's scope from adjacent tools — plugin packaging and hooks, finding an existing skill in a registry, or creating a brand-new skill interactively. — [source](https://llms-explorer.com/tree/claude-code-skills/) *(AI-suggested, synthesized from this pack's existing facts — not extracted from a source document.)*
- Managing token budget across many installed skills, where frontmatter design and skillOverrides determine how much of a skill's content loads into context by default. — [source](https://llms-explorer.com/tree/claude-code-skills/) *(AI-suggested, synthesized from this pack's existing facts — not extracted from a source document.)*

## Project ideas

- Run uvx mcp-scan@latest --skills against a directory of third-party skills before installing any of them, and compare the flagged issues against the skill's actual source. — [source](https://llms-explorer.com/tree/claude-code-skills/) *(AI-suggested, synthesized from this pack's existing facts — not extracted from a source document.)*
- Write a skill with carefully scoped frontmatter, trigger phrases sized to a sensible token budget, then measure how much of it loads by default versus on demand. — [source](https://llms-explorer.com/tree/claude-code-skills/) *(AI-suggested, synthesized from this pack's existing facts — not extracted from a source document.)*
- Deliberately install the same-named skill at both personal and project level and confirm which one Claude Code actually loads, to internalize the precedence order. — [source](https://llms-explorer.com/tree/claude-code-skills/) *(AI-suggested, synthesized from this pack's existing facts — not extracted from a source document.)*
- Build a small CI check that validates a skill's frontmatter fields before it's merged, catching malformed or missing required fields early. — [source](https://llms-explorer.com/tree/claude-code-skills/) *(AI-suggested, synthesized from this pack's existing facts — not extracted from a source document.)*

## Antipatterns

- Installing a skill from an unknown or unaudited source without first running a security scan; published research found a meaningful fraction of scraped skills carried security flaws, some critical, including confirmed malicious payloads. — [source](https://llms-explorer.com/tree/claude-code-skills/) *(AI-suggested, synthesized from this pack's existing facts — not extracted from a source document.)*
- Using this reference for plugin packaging, hook configuration, or agent definitions when that work belongs to a different, dedicated reference. — [source](https://llms-explorer.com/tree/claude-code-skills/) *(AI-suggested, synthesized from this pack's existing facts — not extracted from a source document.)*
- Searching a skill registry manually for an existing skill instead of using the dedicated lookup tool built for that job. — [source](https://llms-explorer.com/tree/claude-code-skills/) *(AI-suggested, synthesized from this pack's existing facts — not extracted from a source document.)*
- Writing a brand-new skill from a description by hand-editing files here instead of using the interactive skill-creation tool built for that job. — [source](https://llms-explorer.com/tree/claude-code-skills/) *(AI-suggested, synthesized from this pack's existing facts — not extracted from a source document.)*

## Known issues

- Skill precedence, enterprise over personal over project, means a locally-installed project skill can be silently overridden by a personal or enterprise-managed skill of the same name, which is easy to miss when debugging why a skill isn't triggering. — [source](https://llms-explorer.com/tree/claude-code-skills/) *(AI-suggested, synthesized from this pack's existing facts — not extracted from a source document.)*
- The security risk in the current skill ecosystem is not hypothetical — a meaningful fraction of scraped skills in the field carry real vulnerabilities, so trust in a skill's source matters as much as trust in its described behavior. — [source](https://llms-explorer.com/tree/claude-code-skills/) *(AI-suggested, synthesized from this pack's existing facts — not extracted from a source document.)*
- This reference is itself a summary layer over a fuller context document; complete coverage of frontmatter fields, token budget management, and skillOverrides requires reading the underlying reference. — [source](https://llms-explorer.com/tree/claude-code-skills/) *(AI-suggested, synthesized from this pack's existing facts — not extracted from a source document.)*
- Skill discovery and composition patterns are still an evolving part of Claude Code, so guidance about CI/CD integration and skill composition can go stale faster than more stable parts of the platform. — [source](https://llms-explorer.com/tree/claude-code-skills/) *(AI-suggested, synthesized from this pack's existing facts — not extracted from a source document.)*

## Context files

- [Claude Code Skills](https://llms-explorer.com/downloads/sources/mdb-context-hub/claude-code-skills.md)
