Skip to main content

reflect

Analyzes chat history and Claude configuration to suggest improvements for CLAUDE.md files and optimize user interactions.

Install this skill

or
53/100

Security score

The reflect skill was audited on Mar 1, 2026 and we found 7 security issues across 2 threat categories, including 1 critical. Review the findings below before installing.

Categories Tested

Security Issues

critical line 57

Piping content to bash shell

SourceSKILL.md
57| **Permission requests** | Bash commands approved 2+ times | Allow list addition |
medium line 33

Access to hidden dotfiles in home directory

SourceSKILL.md
33**Global Configuration (~/.claude/):**
medium line 35

Access to hidden dotfiles in home directory

SourceSKILL.md
35- `~/.claude/CLAUDE.md` - Global instructions
medium line 36

Access to hidden dotfiles in home directory

SourceSKILL.md
36- `~/.claude/settings.json` - Global settings, permissions, allow/deny lists
medium line 37

Access to hidden dotfiles in home directory

SourceSKILL.md
37- `~/.claude/skills/` - User skills directory
low line 80

Access to hidden dotfiles in home directory

SourceSKILL.md
80| Global | ~/.claude/CLAUDE.md | Found/Missing |
low line 81

Access to hidden dotfiles in home directory

SourceSKILL.md
81| Global | ~/.claude/settings.json | Found/Missing |
Scanned on Mar 1, 2026
View Security Dashboard