Analysis Bypass in Claude-Skill-Antivirus Affects Local Executable Files
CVE-2026-84810
7.1HIGH
What is CVE-2026-84810?
The Claude-Skill-Antivirus application suffers from an analysis bypass vulnerability that prevents it from properly scanning executable files located in local skill directories. Instead of thoroughly evaluating all script artifacts, such as Python source and bytecode, the antivirus tool only analyzes the SKILL.md manifest file. This oversight allows attackers to incorporate harmful code into non-manifest files, which may be granted a misleading SAFE verdict with a perfect trust score of 100/100. Consequently, users may unknowingly execute skills containing malicious payloads due to this inadequate scanning mechanism.
Affected Version(s)
claude-skill-antivirus 0 <= 2.1.3
