caterpillar — security grade CAUTION, quality 68/100

Security audit verdict: CAUTION · quality 68/100

Flagged: installs a cron job. Scanned against the SlowMist agent-security taxonomy, refreshed every 8 hours. Full audit →

by alice-dot-io · Claude Skill · ★ 67

Last updated: · Indexed by AgentSkillsHub · Auto-synced every 8h

🔒 Is caterpillar safe to install? View the security audit →

About caterpillar

Caterpillar Security scanner for AI agent skills. Scans for malicious patterns before you install. Install Or via npm: Windows (PowerShell): Requires Node.js = 18. Usage Scan Modes Caterpillar supports three scan modes: Alice — sends skills to the Caterpillar server API for full analysis. OpenAI — uses your own OpenAI API key for LLM analysis. All code is in this repo. Offline — built-in pattern matching, no network calls. All code is in this repo. By default, the mode is auto-detected based on available credentials. Output Formats Each skill gets a grade (A–F) and a score (0–100). Grade F exits with code 1

Quick Facts

Stars67
Forks3
LanguageTypeScript
CategoryClaude Skill
Quality Score67.8890555829485/100
Open Issues1
Last Updated2026-02-16
Created2026-01-29
Platformsclaude-code, node
Est. Tokens~9k

Compatible Skills

These tools work well together with caterpillar for enhanced workflows:

  • markscrub — semantic(0.20)+complementary+shared_fw(openai)+same_lang+similar_pop+shared_platform (65%)

More Claude Skill Tools

Explore other popular claude skill tools:

View all Claude Skill tools →

Popular TypeScript Agent Tools

Frequently Asked Questions

What is caterpillar?

caterpillar is Caterpillar is a security scanning library for AI agent skill files (e.g., Claude Code skills) for dangerous or malicious behavior. It is categorized as a Claude Skill with 67 GitHub stars.

What programming language is caterpillar written in?

caterpillar is primarily written in TypeScript.

How do I install or use caterpillar?

You can find installation instructions and usage details in the caterpillar GitHub repository at github.com/alice-dot-io/caterpillar. The project has 67 stars and 3 forks, indicating an active community.

How this security grade is produced

Grades come from a rule-based scan built on the SlowMist agent-security taxonomy, covering 11 red-flag categories including credential harvesting, data exfiltration, and curl | sh installers. It is a first-layer scan, not a manual audit — we say so rather than overstate it.

The scale of the problem is documented independently: Liu et al. (2026), in a study of 31,132 agent skills, report that 26.1% contain security vulnerabilities. Our own full-catalog census is published as a citable open dataset.

Sources & who's responsible:

View on GitHub → Browse Claude Skill tools