Claude Skills for enterprise: API, Code, EU
Claude Skills in 2026: SKILL.md folders, 20 Skills per API request, code execution 0.05 USD/h after 1,550 free hours. No ZDR. Not on Bedrock or Google Cloud.
TL;DR
Claude Skills are reusable folders of SKILL.md, scripts and reference files. Claude loads the name and description first, then the rest on demand. The API needs the code execution tool and allows at most 20 Skills per request. Agent Skills are not ZDR-eligible. Amazon Bedrock and Google Cloud do not support them.
What are Claude Skills, and how do they load?
Claude Skills are directories with a required SKILL.md plus optional scripts and references. At startup Claude loads only the name and description, about 100 tokens per Skill. It reads the body when the description matches the task. Bundled files cost tokens only when Claude opens them. The name is capped at 64 characters, the description at 1,024.
The Agent Skills overview fetched on 5 October 2026 splits loading into three levels. Level 1 always sits in the system prompt: the YAML fields name and description. Level 2 is the SKILL.md body, which Claude reads with bash once the description matches. Level 3 is extra markdown, scripts and templates. Scripts run in the VM. Only their output enters context.
| Level | When loaded | Token cost | Content |
|---|---|---|---|
| 1 Metadata | At startup | about 100 tokens per Skill | name and description |
| 2 Instructions | On a match | under 5,000 tokens | SKILL.md body |
| 3 Resources | As needed | none until Claude reads them | references, scripts, templates |
The same overview sets the field rules. name may contain only lowercase letters, numbers and hyphens, and must not include the reserved words anthropic or claude. description must be non-empty and must not contain XML tags. It has to say what the Skill does and when Claude should pick it. Authoring best practices keep the SKILL.md body under 500 lines and move detail into linked files.
Anthropic ships four pre-built Skills: pptx, xlsx, docx and pdf. Custom Skills go up through POST /v1/skills as a zip, or live as a directory in Claude Code. API uploads are workspace-wide. Uploads on claude.ai stay with the user who added them and cannot be managed by an admin.
Treat a Skill as software. The security section is blunt: a hostile Skill can invoke tools, read files and send data out. Use Skills you wrote or that Anthropic published. Anything else needs the same review as an internally distributed package. How to approve MCP servers is in Claude MCP for enterprise.
Where do Claude Skills run: API, Code, clouds?
Claude Skills run on claude.ai, the Claude API, Claude Platform on AWS, and Microsoft Foundry when the deployment is Hosted on Anthropic. Claude Code has its own filesystem Skills and does not ship the pre-built document Skills. Amazon Bedrock and Google Cloud list Agent Skills as unsupported. Custom Skills do not sync across surfaces.
The Skills overview and the cloud pages from 5 October 2026 give this matrix:
| Surface | Pre-built document Skills | Custom Skills | Sharing | Runtime network |
|---|---|---|---|---|
| Claude API | pptx, xlsx, docx, pdf |
Skills API, workspace-wide | every workspace member | no network, no package install |
| Claude Platform on AWS | yes | Skills API | workspace-wide | same as the Claude API |
| Microsoft Foundry | yes, Hosted on Anthropic only | Skills API | workspace-wide | same as the Claude API |
| claude.ai | yes, when creating documents | zip in Settings, Pro through Enterprise | uploader only | depends on admin settings |
| Claude Code | no | ~/.claude/skills/ or .claude/skills/ |
personal, project or plugin | full machine network |
| Amazon Bedrock | no | no | n/a | n/a |
| Google Cloud | no | no | n/a | n/a |
Claude in Amazon Bedrock lists Agent Skills, code execution, the Files API and the MCP connector as unsupported. Claude on Google Cloud repeats that list. Teams that need inference in EU member states stay on Bedrock eu. or Google Europe multi-region and lose the Skills API there. The residency routes without Skills are in the Claude GDPR comparison.
Foundry is the hyperscaler exception, and it is narrow. The Foundry guide enables Agent Skills only on Hosted on Anthropic deployments. Hosted on Azure does not. Foundry has no EU data zone for Claude. The Claude API workspace geo is us only. inference_geo accepts only global and us, per the data residency page.
Claude Code is what most engineering teams meet first. The Claude Code Skills page puts personal Skills at ~/.claude/skills/<name>/SKILL.md and project Skills at .claude/skills/<name>/SKILL.md. The directory name becomes /name. Set disable-model-invocation: true when the workflow must stay manual. Cowork and cloud sessions do not read the home directory. They load Skills from the claude.ai account or from the cloned repo. Permissions and sandboxing sit in Claude Code security.
On the API, Skills attach through container and the code execution tool. Without that tool, no Skill starts. A PowerPoint call looks like this:
import anthropic
client = anthropic.Anthropic()
response = client.messages.create(
model="claude-sonnet-5-5",
max_tokens=4096,
container={
"skills": [{"type": "anthropic", "skill_id": "pptx", "version": "latest"}]
},
messages=[{"role": "user", "content": "Create three slides on GDPR roles."}],
tools=[{"type": "code_execution_20250825", "name": "code_execution"}],
)
print(response.to_json())
Use type: "custom" and a skill_01… id for uploaded Skills. Omit version and the request runs latest. The enterprise guide warns that any workspace upload then changes production at once.
What do Claude Skills and code execution cost?
Claude Skills have no separate list price. You pay tokens for metadata, loaded instructions and the reply. Code execution on the Claude API is 0.05 USD per hour per container after 1,550 free hours, with a five-minute minimum. Sonnet 5.5 is 2 / 10 USD per million tokens. Regional and multi-region endpoints add 10 percent from Sonnet 4.5 onward.
The pricing page on 5 October 2026 lists Sonnet 5.5 at 2 USD input and 10 USD output per million tokens, cache reads at 0.20 USD, batch at 1 / 5 USD. Opus 5.5 is 4 / 20 USD. Tool use adds 286 system-prompt tokens on Sonnet 5.5 when tool_choice is auto. Code execution is free when web_search_20260209 or web_fetch_20260209 (or later) sits on the same request. Otherwise the hourly meter applies: 1,550 free hours per organisation per month, then 0.05 USD per hour per container. If the request includes files, the clock runs even when the tool is not called, because files are preloaded.
| Item | Rate | Source |
|---|---|---|
| Sonnet 5.5 input / output | 2 / 10 USD per MTok | Anthropic pricing |
| Opus 5.5 input / output | 4 / 20 USD per MTok | Anthropic pricing |
| Code execution after the free grant | 0.05 USD / h / container, 5 min minimum | Anthropic pricing |
| Free code-execution grant | 1,550 h / month / organisation | Anthropic pricing |
| Regional / multi-region from Sonnet 4.5 | +10 % vs global | Anthropic pricing |
| Foundry and Claude Platform on AWS | 0.01 USD per CCU, 100 CCU = 1.00 USD | Anthropic pricing |
A worked example, our assumption, not a vendor quote: 20 Skills on a request cost about 2,000 metadata tokens at level 1. On Sonnet 5.5 that is 0.004 USD of input before anything runs. If Claude then loads a 4,000-token body and writes 800 tokens, add 0.008 plus 0.008 USD. A code-execution minute inside the free grant is 0 USD extra. After the grant, the five-minute floor is 0.05 USD. Token rates in EUR and the 10 percent EU uplift are in the Claude API pricing comparison.
The feature eligibility table marks Agent Skills as ineligible for both ZDR and HIPAA readiness. Skill definitions and execution data follow the standard retention policy. Code execution may keep container data for up to 30 days. A ZDR customer who still sends Skills steps outside the arrangement for that data. The API does not block the call under ZDR. HIPAA readiness returns a 400.
How should a company govern Claude Skills?
Treat every Skill as software. Read every file, run scripts in a sandbox, require 3 to 5 test cases, and keep the author off the review. Pin the version on the API. Claude Enterprise scanning covers uploads in claude.ai and Cowork only, not the Skills API.
Skills for enterprise, read on 5 October 2026, sets the lifecycle: plan, create and review, test, deploy, monitor, iterate or retire. The Skills API has no usage analytics. You log which skill_id each request carried.
- Read SKILL.md, every referenced file and every script.
- Run scripts in an isolated environment and check that the output matches the description.
- Hunt for instructions that drop safety rules, hide actions or encode data into the reply.
- Search for network patterns:
http,curl,fetch,requests,urllib. - Ban hardcoded credentials. Secrets belong in the environment or a secret store.
- List bash commands, file access and MCP references. File read plus network is the dangerous pair.
- Check destination URLs and store checksums of the approved version.
- Write 3 to 5 cases: should trigger, should not, edge. Run them on Haiku, Sonnet and Opus.
The scan at claude.ai > Organization settings > Skills blocks failed or unfinished scans. A warning still lets people use the Skill. It does not cover /v1/skills or Console uploads, Skills that were already present, or orgs on CMEK, ZDR or HIPAA readiness. For the API, the checklist and a pinned version remain the control.
Keep the active set small. Each description competes in the system prompt. The API cap of 20 is a hard limit, not a target. Bundle by role: sales, engineering, finance. Git is the source of truth. Production pins skver_… or the dated Anthropic Skill id, not latest.
Claude Skills vs MCP: which one do you need?
Claude Skills package knowledge and local scripts. MCP connects Claude to live systems. A Skill with no network on the API cannot write a ticket. An MCP server without an allowlist can. We recommend Skills for repeatable workflows and templates, MCP for live data. Each needs its own approval path.
Skills on the Claude API have no network and no runtime package install. MCP servers in Claude Code share the user’s network. A Skill that curls your ERP does not belong on the API. The same Skill in Claude Code is an exfiltration path if the description lies. The enterprise checklist rates scripts, MCP references and network access as high risk.
| Question | Claude Skills | Claude MCP |
|---|---|---|
| What it is | A folder of instructions and optional code | A protocol to a running server |
| When it loads | Description matches, or /name in Claude Code |
The server is configured and allowed |
| Network on the API | none | the server reaches the target network |
| Central control on claude.ai | no, per-user upload | connector approval by plan |
| Central control on the API | yes, workspace, version pin | your own gateway or proxy |
| EU inference on Bedrock or Google | not available | yes, if you host the server |
Our line: templates, report layouts and writing rules as a Skill. CRM, tickets and records as MCP behind an allowlist and OAuth. Agents that need both and must stay in the EU belong on the Claude Agent SDK on Bedrock or Google Cloud, with Skills baked into the image rather than loaded through the Anthropic Skills API.
FAQ
What do Claude Skills actually cost?
There is no Skill tariff. You pay tokens for metadata, loaded files and the reply, plus code execution after 1,550 free hours at 0.05 USD per hour per container. A request with 20 Skills and one triggered SKILL.md often stays under a cent of tokens on Sonnet 5.5. Cost jumps when you combine a large context, Opus 5.5 and many container hours.
Claude Skills vs MCP: which should we roll out first?
Skills first, for workflows that do not touch a live system: slides, reports, review checklists. MCP second, when Claude must write into tickets, repos or records. Skills without network are the smaller API attack surface. MCP without an allowlist is the larger one. That order saves review hours.
Do Claude Skills work on Amazon Bedrock in the EU?
No. The Bedrock page lists Agent Skills and code execution as unsupported. Google Cloud does the same. EU inference and the Skills API do not overlap in the current docs. Foundry offers Skills only on Hosted on Anthropic, and it has no EU data zone.
Does ZDR cover Agent Skills?
No. The eligibility table marks Agent Skills and code execution as not ZDR-eligible. Container data may sit for up to 30 days. HIPAA readiness rejects the combination with a 400. ZDR does not block the call. You leave the arrangement for that data.
Can IT push custom Skills to everyone on claude.ai?
No. A claude.ai upload stays with the uploader. Admins cannot distribute Skills organisation-wide there. Workspace-wide distribution is the Skills API. Claude Code distributes through Git, plugins or managed settings. The three paths stay separate.
Is the Enterprise scan enough to approve a Skill?
No. The scan covers new uploads in claude.ai and Cowork only. The Skills API, the Console, older uploads, and CMEK, ZDR or HIPAA orgs sit outside it. Anthropic calls the scan a complement to the checklist, not a replacement.
Sources
- Anthropic docs: Agent Skills (5 October 2026)
- Anthropic docs: Using Agent Skills with the API (5 October 2026)
- Anthropic docs: Skills for enterprise (5 October 2026)
- Anthropic docs: Pricing (5 October 2026)
- Anthropic docs: API and data retention (5 October 2026)
- Anthropic docs: Data residency (5 October 2026)
- Claude Code docs: Skills (5 October 2026)
- Anthropic docs: Claude on Google Cloud (5 October 2026)
- Anthropic docs: Claude in Amazon Bedrock (5 October 2026)
- Anthropic docs: Claude in Microsoft Foundry (5 October 2026)