claude-skill-antivirus Analysis Bypass via Manifest-Only Local Directory Scan
41Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendcvss 7.1epss 0.3%
exploitation probability
0.3%top 82% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
claude-skill-antivirus fails to analyze executable files when scanning local skill directories, reading only SKILL.md while ignoring Python source, bytecode, and other artifacts in the scripts directory. Attackers can distribute skills with malicious code in non-manifest files that receive a SAFE verdict with 100/100 trust score despite containing unanalyzed executable payloads.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
Affected products
claude-world · claude-skill-antiviruspublic PoCs found — 1
cve_referencegithub.com/nedlir/skills-scanner-bypassunverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
https://github.com/claude-world/claude-skill-antivirushttps://github.com/claude-world/claude-skill-antivirus/blob/v2.1.3/src/scanner/index.jshttps://github.com/claude-world/claude-skill-antivirus/blob/v2.1.3/src/utils/downloader.jshttps://github.com/claude-world/claude-skill-antivirus/issues/33https://github.com/nedlir/skills-scanner-bypasshttps://www.vulncheck.com/advisories/claude-skill-antivirus-analysis-bypass-via-manifest-only-local-directory-scan