Hook

Their other posts in the index, biggest breakout first.
Stop installing random Claude skills off GitHub. You're running a stranger's instructions on your own setup, and most of them are junk anyway. A skill isn't a plugin, it's an instruction set Claude actually follows. If a bad one goes unchecked, it can tell Claude to do things you never asked for. So before you install anything, paste the link for your skill, read the skill and tell me every file it touches, every command it runs, and anything it sends anywhere - in plain English. Notice what you did not ask. Is this safe? Because anything sketchy will just tell you it's safe. You ask what it actually does. Then you decide for yourself. Here's what to look for. Green flags. It stays in its lane. Uses expected tools. Does what it promised to do. Red flags. It sends data somewhere you don't recognize. Reads what it shouldn't. Or downloads and runs code blind. Ten seconds, the garbage filters itself out. Hope this helps. See you on Day 4.