Before you install skills from strangers, let me tell you about ClawHavoc. Researchers found malicious skills on ClawHub. That was % of all submitted skills at the time. The attacks ranged from exfiltrating environment variables to injecting prompt overrides that changed agent behavior.
You can protect yourself with habits. First, only install skills with verified publisher badges. Second, review the SKILL.md before installing to check what environment variables and binaries it requests. Third, run skills in sandboxed mode with --sandbox so they cannot access files outside their own directory. ClawHub now flags skills that request unusual permission combinations, but no automated system catches everything.