Framework how-tos

Agent Skills Security: How to Find, Scan and Control the Skills on Employee Computers

Find every Claude Code, Codex and Cursor skill on employee computers, scan each for malicious instructions, and allow only approved skills. Step-by-step guide.

Updated Oct 10, 2026

Last reviewed: October 2026

By Contro1 team (Agent control for organizations)

Coding agents load skills from folders on each employee’s computer, and nobody reviews them. To control them: install the contro1 CLI once per computer so it reports every skill daily, scan each one with NVIDIA SkillSpector and Cisco Skill Scanner, deliver approved skills from Contro1 over MCP, block local skills in Claude Code with a managed setting, and get told the same day when anything else appears.

See it in Contro1

Turning on the daily skills report on a computer, allowing only skills from Contro1, and what an administrator sees when someone installs a dangerous skill anyway. The real Contro1 Skills page, with demo data.

Find, scan and control agent skills on employee computers with Contro1: Interface shown with demo data. Northbeam is a fictional company.

The short answer

Agent skills are folders with a SKILL.md file that Claude Code, Codex, Cursor and Gemini CLI load from each employee’s computer. They change what the agent does, they can include scripts, and they arrive from marketplaces, repositories and copy-paste without review. Treat them like software installed on a laptop.

A complete control has four parts: an inventory of every skill on every computer, a security scan of each one, one approved source for the skills people need, and a policy that blocks or flags everything else. Contro1 provides all four, and the access gateway still decides what any agent may actually do.

Why agent skills are a security problem

A skill is instructions plus optional code, loaded into a trusted session. A malicious or careless one can tell an agent to download and run a script, send data out, or hide what it is doing from the person using it. Researchers have found exactly that in public skills: a large empirical study of skills in the wild catalogued malicious ones with data exfiltration and remote code patterns, and Datadog Security Labs showed that a cloned repository can bring skills into a Claude Code session without anyone installing them on purpose.

The problem is ownership. Skills live in personal folders on laptops, outside any central registry. The Cloud Security Alliance puts it simply: without an inventory, every other control is blind. This is the same shadow AI problem organizations already know from unsanctioned AI tools, one level deeper.

Datadog Security Labs: Malicious coding agent skills and dynamic context · Malicious Agent Skills in the Wild: a large-scale empirical study (arXiv) · Cloud Security Alliance: 5 Claude agent skills risks every CISO should know

Where skills hide on a computer

Each agent loads skills from its own folders. These are the places an inventory has to cover. The contro1 CLI also reads Windsurf, Goose, Kiro, Roo Code, Continue, Qwen Code, Factory Droid and other agents with a documented skills folder.

AgentWhere skills load fromCan an administrator block local skills?
Claude Code~/.claude/skills, .claude/skills in a project, installed plugins, enterprise managed folderYes, with the managed setting strictPluginOnlyCustomization
Codex~/.codex/skills, .codex/skills in a projectNo documented setting today: detect and scan
Cursor~/.cursor/skills, .cursor/skills in a projectNo documented setting today: detect and scan
Gemini CLI~/.gemini/skillsNo documented setting today: detect and scan
GitHub Copilot~/.copilot/skills, .github/skills in a projectNo documented setting today: detect and scan
Any Agent Skills tool~/.agents/skills, .agents/skills in a project (shared by Codex, Cline, OpenCode, Amp and others)No documented setting today: detect and scan
OpenClaw~/.openclaw/skills, skills/ and .agents/skills in each workspace, skills.load.extraDirsNo central setting documented: detect and scan
Hermes Agent~/.hermes/skills (by category), .hermes/skills in a project, external_dirs in config.yamlNo central setting documented: detect and scan
NanoClawcontainer/skills in the NanoClaw install, mounted into every agent containerNo central setting documented: detect and scan
Claude CoworkSkills added under Customize > Skills in the Claude desktop app, kept in its app data folderNo central lock documented for skills a person adds: detect and scan
Any agent connected to Contro1Delivered over MCP by Contro1, nothing installedControlled in Contro1: versions, approvals, who gets what

Claude Code docs: Skills (where skills load from) · OpenAI: Codex admin setup and managed configuration · OpenClaw docs: Skills (load locations and precedence) · Hermes Agent docs: Skills System · NanoClaw docs: Skills system

How to find, scan and control agent skills, step by step

Every step below is in the Contro1 Skills page. Each person does steps 1 to 3 once on their computer; an administrator does the rest.

Install the contro1 CLI on the computer

Once per computer, not per tool: one install covers Claude Code, Codex, Cursor and Gemini CLI. Windows: irm https://contro1.com/install.ps1 | iex. macOS and Linux: curl -fsSL https://contro1.com/install.sh | sh.

Sign in

contro1 auth login opens the browser once. The CLI receives a limited token that can report skills and cannot change anything.

Turn on the daily report

contro1 skills schedule. It checks every four hours and reports at most once a day, so a laptop that was off still reports the same day. Nothing runs on screen.

See every skill, scanned

In Skills, every reported skill appears under the person, their department and the tool, scanned by NVIDIA SkillSpector, Cisco Skill Scanner and a Contro1 check. Skills > Scan agents shows which connected coding agents still need the CLI, and which computers went quiet.

Deliver approved skills from Contro1

Write or import the skills people need, publish a version, and push it to the whole organization, a department, a person or one agent. Connected agents receive them over MCP, so nobody needs to install a skill.

Allow only skills from Contro1

In Skills > Approval policy, choose Only skills from Contro1. Every other skill is flagged as outside policy, and administrators, the department manager and the person are emailed when a new one appears.

Lock Claude Code

Deploy the managed setting below with Intune, Jamf, Group Policy or the managed settings file. Claude Code then stops loading personal and project skills, and users cannot override it. Scan agents shows which computers have the lock.

managed-settings.json
{
  "strictPluginOnlyCustomization": ["skills"],
  "strictKnownMarketplaces": []
}

Claude Code docs: Deploy managed settings · Claude Code docs: strictPluginOnlyCustomization and other settings

What happens when someone installs a skill anyway

Contro1 does not delete files on anyone’s computer. If the skill is useful, an administrator adopts it into the library, edits it, and pushes it back through Contro1, where it is versioned and approved like every other skill.

  1. Step 1

    Installed

    A person adds a skill to Codex or Cursor, or to a Claude Code without the lock.

  2. Step 2

    Reported

    The daily report from that computer includes it.

  3. Step 3

    Scanned

    NVIDIA SkillSpector, Cisco Skill Scanner and Contro1 check it.

  4. Step 4

    Flagged

    Marked outside policy, with the person, computer and tool.

  5. Step 5

    Told

    Administrators and the department manager are emailed; the person is asked to remove it.

What can be blocked, and what can only be detected

Be precise about this with your security team. Claude Code supports an organization-wide lock: with strictPluginOnlyCustomization covering skills in managed settings, it stops loading skills from personal and project folders, and managed settings sit above every user and project setting. Codex, Cursor and Gemini CLI have no equivalent documented setting today, so for them the control is detection: the daily report finds what is installed, the same day.

Two things hold in every case. Skills delivered by Contro1 reach agents over MCP, so the Claude Code lock does not stop them. And a skill is guidance, not permission: whatever a local skill tells an agent to do, the action still has to pass the Contro1 gateway, which checks the agent’s access before anything runs.

Scanning helps, and it is not enough on its own

Open-source scanners such as NVIDIA SkillSpector and Cisco Skill Scanner catch known patterns: remote scripts piped to a shell, hidden instructions, exfiltration, prompt injection. Contro1 runs both on every version, every import and every skill found on a computer, and a skill they judge dangerous needs an administrator, who approves it by name in the audit log.

Scanners can also be bypassed. OWASP’s Agentic Skills Top 10 lists poor scanning as a risk of its own, and the Cloud Security Alliance reported that no single scanner caught every bypass technique. Use the scan as one layer: combine it with one approved source, the policy, and action-level permissions at the gateway.

OWASP Agentic Skills Top 10: AST08 Poor Scanning · Cloud Security Alliance: AI agent skill scanners bypassed across the board

A checklist for security teams

ControlHow in Contro1Done when
Inventorycontro1 skills schedule on every computerScan agents shows every employee reporting
ScanAutomatic on every reported skill and every versionNo dangerous skill is unreviewed
One approved sourceSkills library, pushed over MCPTeams get what they need without installing
PolicyApproval policy: Only skills from Contro1Outside-policy skills trend to zero
Enforcement where possibleClaude Code managed settingScan agents shows Claude Code locked
Least privilegeAccess grants and approvals at the gatewayA skill cannot make an agent do more than its access allows

Frequently asked questions

What is an agent skill?

A folder with a SKILL.md file, and optional scripts and references, that a coding agent such as Claude Code, Codex or Cursor loads to learn how to do a task. Skills change what the agent does, so they need the same review as installed software.

Are agent skills a security risk?

Yes. A skill can tell an agent to run downloaded code, send data out or hide its actions, and researchers have found malicious skills in public marketplaces. Skills on employee laptops are usually unreviewed and invisible to the organization.

How do I find which skills my employees installed?

Install the contro1 CLI once on each computer, sign in, and run contro1 skills schedule. Every day it reports the skills in Claude Code, Codex, Cursor and Gemini CLI, and Contro1 shows them by person, department and tool.

Do I need to install something for each coding agent?

No. One install of the contro1 CLI per computer covers every coding agent on it.

How are skills scanned for malicious instructions?

Contro1 scans every reported skill with NVIDIA SkillSpector, Cisco Skill Scanner and its own checks. A skill judged dangerous needs an administrator’s named approval before it can reach agents through Contro1.

Can I block employees from installing Claude Code skills?

Yes. Deploy the managed setting strictPluginOnlyCustomization with skills, through MDM, Group Policy or the managed settings file. Claude Code then loads skills only from plugins and managed sources, and users cannot override it. Skills from Contro1 still arrive over MCP.

Can I block skills in Codex or Cursor?

There is no documented setting for that today. Contro1 detects skills installed in Codex and Cursor in the daily report, scans them, and tells administrators when one appears outside policy.

Does Contro1 delete skills from employee computers?

No. It reports, scans and flags them, and tells the person and their managers. Removing a skill, or adopting it into the approved library, is a decision people make.

See, scan and control the skills on every computer.

Start free with Contro1: install the CLI on one computer, turn on the daily report, and see its skills and their scan results in minutes. No credit card required.

Get started with Contro1

Related resources

Organizational skills

Push skills to every agent over MCP, see and scan every skill employees install, and allow only skills from Contro1. With versions, rollback and approvals.