HACKER Q&A
📣 camicortazar

Is there a market for a security-audited Claude Code skills newsletter?


I've been using Claude Code heavily and kept running into the same frustration: there are thousands of skills out there but no reliable way to know if they're any good or safe to install. Snyk's ToxicSkills research found 36.82% of publicly available skills contain security flaws, 13.4% critical.

I'm building The Skill Shortlist — a bi-weekly newsletter that reviews and security-audits Claude Code skills before they reach subscribers. Every skill is scored across six criteria and gets a clear verdict. If it fails the security check, it never runs. Paid tier includes the reviewed SKILL.md file ready to install.

A few things I'm genuinely unsure about: - Is this a real pain point or is the audience too small right now? - Would developers pay for curated, ready-to-install skill files or is this something people prefer to DIY? - Any comparable newsletters in adjacent spaces that have worked (or failed) that I should study?

Still pre-launch. Happy to be talked out of it.