
This is actually a documentation skill that helps you identify malicious repositories disguised as cracked software, not a tool that scans your system for malware. It walks through red flags like empty READMEs, SEO-stuffed keywords, fake stars, and suspicious topics like "defender-bypass." The irony here is thick: it's teaching threat identification by documenting a real malicious repo that pretends to offer pirated Bitdefender. Useful if you're training a model to spot software supply chain attacks or building educational content about GitHub-based malware distribution. The skill itself has mixed security audits (Gen Agent Trust Hub and Snyk warn, Socket passes), which tells you everything about how messy security tooling can be.
npx -y skills add aradotso/security-skills --skill malware-detection-and-removal --agent claude-codeInstalls into .claude/skills of the current project.
Select a file.