Security Audit
claude-dev-suite/claude-dev-suite:skills/api-design/swagger-dotnet
github.com/claude-dev-suite/claude-dev-suiteTrust Assessment
claude-dev-suite/claude-dev-suite:skills/api-design/swagger-dotnet received a trust score of 85/100, placing it in the Mostly Trusted category. This skill has passed most security checks with only minor considerations noted.
SkillShield's automated analysis identified 1 finding: 0 critical, 0 high, 0 medium, and 1 low severity. Key findings include Excessive 'Write' and 'Edit' permissions for a reference skill.
The analysis covered 4 layers: Manifest Analysis, Static Code Analysis, Dependency Graph, LLM Behavioral Safety. All layers scored 70 or above, reflecting consistent security practices.
Last analyzed on March 16, 2026 (commit 8c8434ef). SkillShield performs automated 4-layer security analysis on AI skills and MCP servers.
Layer Breakdown
Behavioral Risk Signals
Security Findings1
| Severity | Finding | Layer | Location | |
|---|---|---|---|---|
| LOW | Excessive 'Write' and 'Edit' permissions for a reference skill The skill is described as a 'quick reference' for Swagger/NSwag, primarily providing informational content and code examples. While an AI agent utilizing this skill might eventually need to modify files to implement the suggested configurations, the skill itself, as a documentation source, does not inherently require 'Write' or 'Edit' permissions. Granting such broad permissions to a passive reference skill increases the potential attack surface if the agent's execution context were to be compromised through prompt injection or other means, allowing unintended file modifications. Re-evaluate the necessity of 'Write' and 'Edit' permissions for this skill. If the skill's primary function is to provide information, consider restricting permissions to 'Read', 'Grep', and 'Glob'. If the skill is intended to guide code modification, ensure this is clearly stated and that the agent's use of these permissions is tightly controlled and validated. | LLM | SKILL.md:1 |
Scan History
Embed Code
[](https://skillshield.io/report/bcad1ed634bdaf7d)
Powered by SkillShield