Agent Skills Security: How to Find, Scan and Control the Skills on Employee Computers
Find every Claude Code, Codex and Cursor skill on employee computers, scan each for malicious instructions, and allow only approved skills. Step-by-step guide.
Updated Oct 10, 2026
Last reviewed: October 2026
By Contro1 team (Agent control for organizations)
Coding agents load skills from folders on each employee’s computer, and nobody reviews them. To control them: install the contro1 CLI once per computer so it reports every skill daily, scan each one with NVIDIA SkillSpector and Cisco Skill Scanner, deliver approved skills from Contro1 over MCP, block local skills in Claude Code with a managed setting, and get told the same day when anything else appears.
See it in Contro1
Turning on the daily skills report on a computer, allowing only skills from Contro1, and what an administrator sees when someone installs a dangerous skill anyway. The real Contro1 Skills page, with demo data.
Find, scan and control agent skills on employee computers with Contro1: Interface shown with demo data. Northbeam is a fictional company.
The short answer
Agent skills are folders with a SKILL.md file that Claude Code, Codex, Cursor and Gemini CLI load from each employee’s computer. They change what the agent does, they can include scripts, and they arrive from marketplaces, repositories and copy-paste without review. Treat them like software installed on a laptop.
A complete control has four parts: an inventory of every skill on every computer, a security scan of each one, one approved source for the skills people need, and a policy that blocks or flags everything else. Contro1 provides all four, and the access gateway still decides what any agent may actually do.
Why agent skills are a security problem
A skill is instructions plus optional code, loaded into a trusted session. A malicious or careless one can tell an agent to download and run a script, send data out, or hide what it is doing from the person using it. Researchers have found exactly that in public skills: a large empirical study of skills in the wild catalogued malicious ones with data exfiltration and remote code patterns, and Datadog Security Labs showed that a cloned repository can bring skills into a Claude Code session without anyone installing them on purpose.
The problem is ownership. Skills live in personal folders on laptops, outside any central registry. The Cloud Security Alliance puts it simply: without an inventory, every other control is blind. This is the same shadow AI problem organizations already know from unsanctioned AI tools, one level deeper.
Each agent loads skills from its own folders. These are the places an inventory has to cover. The contro1 CLI also reads Windsurf, Goose, Kiro, Roo Code, Continue, Qwen Code, Factory Droid and other agents with a documented skills folder.
Agent
Where skills load from
Can an administrator block local skills?
Claude Code
~/.claude/skills, .claude/skills in a project, installed plugins, enterprise managed folder
Yes, with the managed setting strictPluginOnlyCustomization
Codex
~/.codex/skills, .codex/skills in a project
No documented setting today: detect and scan
Cursor
~/.cursor/skills, .cursor/skills in a project
No documented setting today: detect and scan
Gemini CLI
~/.gemini/skills
No documented setting today: detect and scan
GitHub Copilot
~/.copilot/skills, .github/skills in a project
No documented setting today: detect and scan
Any Agent Skills tool
~/.agents/skills, .agents/skills in a project (shared by Codex, Cline, OpenCode, Amp and others)
No documented setting today: detect and scan
OpenClaw
~/.openclaw/skills, skills/ and .agents/skills in each workspace, skills.load.extraDirs
No central setting documented: detect and scan
Hermes Agent
~/.hermes/skills (by category), .hermes/skills in a project, external_dirs in config.yaml
No central setting documented: detect and scan
NanoClaw
container/skills in the NanoClaw install, mounted into every agent container
No central setting documented: detect and scan
Claude Cowork
Skills added under Customize > Skills in the Claude desktop app, kept in its app data folder
No central lock documented for skills a person adds: detect and scan
Any agent connected to Contro1
Delivered over MCP by Contro1, nothing installed
Controlled in Contro1: versions, approvals, who gets what
How to find, scan and control agent skills, step by step
Every step below is in the Contro1 Skills page. Each person does steps 1 to 3 once on their computer; an administrator does the rest.
Install the contro1 CLI on the computer
Once per computer, not per tool: one install covers Claude Code, Codex, Cursor and Gemini CLI. Windows: irm https://contro1.com/install.ps1 | iex. macOS and Linux: curl -fsSL https://contro1.com/install.sh | sh.
Sign in
contro1 auth login opens the browser once. The CLI receives a limited token that can report skills and cannot change anything.
Turn on the daily report
contro1 skills schedule. It checks every four hours and reports at most once a day, so a laptop that was off still reports the same day. Nothing runs on screen.
See every skill, scanned
In Skills, every reported skill appears under the person, their department and the tool, scanned by NVIDIA SkillSpector, Cisco Skill Scanner and a Contro1 check. Skills > Scan agents shows which connected coding agents still need the CLI, and which computers went quiet.
Deliver approved skills from Contro1
Write or import the skills people need, publish a version, and push it to the whole organization, a department, a person or one agent. Connected agents receive them over MCP, so nobody needs to install a skill.
Allow only skills from Contro1
In Skills > Approval policy, choose Only skills from Contro1. Every other skill is flagged as outside policy, and administrators, the department manager and the person are emailed when a new one appears.
Lock Claude Code
Deploy the managed setting below with Intune, Jamf, Group Policy or the managed settings file. Claude Code then stops loading personal and project skills, and users cannot override it. Scan agents shows which computers have the lock.
Contro1 does not delete files on anyone’s computer. If the skill is useful, an administrator adopts it into the library, edits it, and pushes it back through Contro1, where it is versioned and approved like every other skill.
Step 1
Installed
A person adds a skill to Codex or Cursor, or to a Claude Code without the lock.
Step 2
Reported
The daily report from that computer includes it.
Step 3
Scanned
NVIDIA SkillSpector, Cisco Skill Scanner and Contro1 check it.
Step 4
Flagged
Marked outside policy, with the person, computer and tool.
Step 5
Told
Administrators and the department manager are emailed; the person is asked to remove it.
What can be blocked, and what can only be detected
Be precise about this with your security team. Claude Code supports an organization-wide lock: with strictPluginOnlyCustomization covering skills in managed settings, it stops loading skills from personal and project folders, and managed settings sit above every user and project setting. Codex, Cursor and Gemini CLI have no equivalent documented setting today, so for them the control is detection: the daily report finds what is installed, the same day.
Two things hold in every case. Skills delivered by Contro1 reach agents over MCP, so the Claude Code lock does not stop them. And a skill is guidance, not permission: whatever a local skill tells an agent to do, the action still has to pass the Contro1 gateway, which checks the agent’s access before anything runs.
Scanning helps, and it is not enough on its own
Open-source scanners such as NVIDIA SkillSpector and Cisco Skill Scanner catch known patterns: remote scripts piped to a shell, hidden instructions, exfiltration, prompt injection. Contro1 runs both on every version, every import and every skill found on a computer, and a skill they judge dangerous needs an administrator, who approves it by name in the audit log.
Scanners can also be bypassed. OWASP’s Agentic Skills Top 10 lists poor scanning as a risk of its own, and the Cloud Security Alliance reported that no single scanner caught every bypass technique. Use the scan as one layer: combine it with one approved source, the policy, and action-level permissions at the gateway.
Automatic on every reported skill and every version
No dangerous skill is unreviewed
One approved source
Skills library, pushed over MCP
Teams get what they need without installing
Policy
Approval policy: Only skills from Contro1
Outside-policy skills trend to zero
Enforcement where possible
Claude Code managed setting
Scan agents shows Claude Code locked
Least privilege
Access grants and approvals at the gateway
A skill cannot make an agent do more than its access allows
Frequently asked questions
What is an agent skill?
A folder with a SKILL.md file, and optional scripts and references, that a coding agent such as Claude Code, Codex or Cursor loads to learn how to do a task. Skills change what the agent does, so they need the same review as installed software.
Are agent skills a security risk?
Yes. A skill can tell an agent to run downloaded code, send data out or hide its actions, and researchers have found malicious skills in public marketplaces. Skills on employee laptops are usually unreviewed and invisible to the organization.
How do I find which skills my employees installed?
Install the contro1 CLI once on each computer, sign in, and run contro1 skills schedule. Every day it reports the skills in Claude Code, Codex, Cursor and Gemini CLI, and Contro1 shows them by person, department and tool.
Do I need to install something for each coding agent?
No. One install of the contro1 CLI per computer covers every coding agent on it.
How are skills scanned for malicious instructions?
Contro1 scans every reported skill with NVIDIA SkillSpector, Cisco Skill Scanner and its own checks. A skill judged dangerous needs an administrator’s named approval before it can reach agents through Contro1.
Can I block employees from installing Claude Code skills?
Yes. Deploy the managed setting strictPluginOnlyCustomization with skills, through MDM, Group Policy or the managed settings file. Claude Code then loads skills only from plugins and managed sources, and users cannot override it. Skills from Contro1 still arrive over MCP.
Can I block skills in Codex or Cursor?
There is no documented setting for that today. Contro1 detects skills installed in Codex and Cursor in the daily report, scans them, and tells administrators when one appears outside policy.
Does Contro1 delete skills from employee computers?
No. It reports, scans and flags them, and tells the person and their managers. Removing a skill, or adopting it into the approved library, is a decision people make.
See, scan and control the skills on every computer.
Start free with Contro1: install the CLI on one computer, turn on the daily report, and see its skills and their scan results in minutes. No credit card required.
Push skills to every agent over MCP, see and scan every skill employees install, and allow only skills from Contro1. With versions, rollback and approvals.
Built a useful Claude Code agent? Learn how to share its skills, deploy it for your team, manage permissions and credentials, and govern it as a team agent.