Flagged: installs a cron job. Scanned against the SlowMist agent-security taxonomy, refreshed every 8 hours. Full audit →
by alice-dot-io · Claude Skill · ★ 67
Last updated: · Indexed by AgentSkillsHub · Auto-synced every 8h
🔒 Is caterpillar safe to install? View the security audit →
Caterpillar Security scanner for AI agent skills. Scans for malicious patterns before you install. Install Or via npm: Windows (PowerShell): Requires Node.js = 18. Usage Scan Modes Caterpillar supports three scan modes: Alice — sends skills to the Caterpillar server API for full analysis. OpenAI — uses your own OpenAI API key for LLM analysis. All code is in this repo. Offline — built-in pattern matching, no network calls. All code is in this repo. By default, the mode is auto-detected based on available credentials. Output Formats Each skill gets a grade (A–F) and a score (0–100). Grade F exits with code 1
| Stars | 67 |
| Forks | 3 |
| Language | TypeScript |
| Category | Claude Skill |
| Quality Score | 67.8890555829485/100 |
| Open Issues | 1 |
| Last Updated | 2026-02-16 |
| Created | 2026-01-29 |
| Platforms | claude-code, node |
| Est. Tokens | ~9k |
These tools work well together with caterpillar for enhanced workflows:
Explore other popular claude skill tools:
caterpillar is Caterpillar is a security scanning library for AI agent skill files (e.g., Claude Code skills) for dangerous or malicious behavior. It is categorized as a Claude Skill with 67 GitHub stars.
caterpillar is primarily written in TypeScript.
You can find installation instructions and usage details in the caterpillar GitHub repository at github.com/alice-dot-io/caterpillar. The project has 67 stars and 3 forks, indicating an active community.
Grades come from a rule-based scan built on the SlowMist agent-security taxonomy, covering 11 red-flag categories including credential harvesting, data exfiltration, and curl | sh installers. It is a first-layer scan, not a manual audit — we say so rather than overstate it.
The scale of the problem is documented independently: Liu et al. (2026), in a study of 31,132 agent skills, report that 26.1% contain security vulnerabilities. Our own full-catalog census is published as a citable open dataset.
Sources & who's responsible: