Security Audit
claude-dev-suite/claude-dev-suite:skills/authentication/nextauth
github.com/claude-dev-suite/claude-dev-suiteTrust Assessment
claude-dev-suite/claude-dev-suite:skills/authentication/nextauth received a trust score of 85/100, placing it in the Mostly Trusted category. This skill has passed most security checks with only minor considerations noted.
SkillShield's automated analysis identified 1 finding: 0 critical, 0 high, 1 medium, and 0 low severity. Key findings include Overly broad write/edit permissions for a knowledge skill.
The analysis covered 4 layers: Manifest Analysis, Static Code Analysis, Dependency Graph, LLM Behavioral Safety. All layers scored 70 or above, reflecting consistent security practices.
Last analyzed on March 16, 2026 (commit 8c8434ef). SkillShield performs automated 4-layer security analysis on AI skills and MCP servers.
Layer Breakdown
Behavioral Risk Signals
Security Findings1
| Severity | Finding | Layer | Location | |
|---|---|---|---|---|
| MEDIUM | Overly broad write/edit permissions for a knowledge skill The skill 'nextauth' is described as providing 'Core Knowledge' and documentation for NextAuth.js. However, it declares 'Write' and 'Edit' permissions. These permissions appear excessive for a skill primarily focused on providing information and guidance, as its current content does not demonstrate a need to modify files. Granting such broad permissions to an informational skill could allow it to make unauthorized changes to the codebase if prompted to do so, exceeding its stated purpose. Re-evaluate the necessity of 'Write' and 'Edit' permissions for this skill. If the skill's primary purpose is purely informational, these permissions should be removed. If the skill is intended to actively implement or modify NextAuth configurations, the skill's description and documentation should be updated to clearly reflect this, and the skill's implementation should strictly control when and how these powerful permissions are utilized. | LLM | SKILL.md:3 |
Scan History
Embed Code
[](https://skillshield.io/report/7f17004dbe73ede8)
Powered by SkillShield