Somewhere in your Claude settings there is a list of skills. You may have added to it back in July, when Record a Skill made it easy to build one by demonstration. You may have installed one from a link someone sent you. Either way, you probably haven't looked at that list since.
Two things changed this month that make it worth reading again, and I haven't seen anyone connect them.
On August 6, Anthropic shipped automated scanning that checks third party skills and plugins for malicious content when they're uploaded or edited. It's in beta, and it's Enterprise only. On Free, Pro or Max, the skills you install are not scanned.
On August 12, Claude's Chrome side panel became a full Cowork session. Anthropic's own wording is that skills and connectors you already have configured "work automatically without additional setup." Claude can read the page you're on and act on it using the logins already sitting in your browser: clicking links, navigating, entering text, filling in forms. It's live on Max and Team, and Anthropic says Pro gets it in the coming weeks. That's why this is landing now rather than later. Anthropic's own note concedes that browser agents "remain vulnerable to prompt injection" and that its safeguards "reduce risk but cannot eliminate it."
Put those together and a skill stops resembling a saved prompt. It behaves more like a browser extension, except there's no review process on your plan, you can't see the moment it activates, and the browser it runs inside is logged into your email, your bank and your shopping accounts.
Outside researchers have started counting. One analysis of 42,447 published skills reported that 26.1% carried at least one vulnerability and 13.4% had a critical problem, including malware, prompt injection or exposed credentials. A separate audit put the vulnerability rate at 36.8%. Those are third party figures drawn from public repositories, not Anthropic's numbers and not a verdict on your particular list. Treat them as a base rate.
So, four checks to run before you install another one.
Open Settings and look for Code execution and file creation. If it's off, skills don't execute. If it's on, they can, and most people switched it on for one document task months ago and never switched it back.
It's under Customize > Skills. Toggle off anything you didn't deliberately install or don't currently use. The toggles are per skill and reversible, so there's no cost to being aggressive.
Anthropic's own help documentation says to install only from trusted sources, and names prompt injection and data exfiltration as the reasons. Anthropic publishes its official skills in a public repository. A GitHub link a stranger posted in a thread isn't the same thing, even when it works.
Letting Claude into Chrome is its own permission, and it acts there with your existing logins, so keep that decision apart from any skill you've already approved.
A simple rule: a skill is a permission, not a preference. Open that list the way you'd open an app's permissions screen, and set a reminder to open it again in a month.
If you find something on there you don't remember installing, hit reply and tell me what it was. I read all of them.