A skill is instructions your agent follows with your permissions.
A SKILL.md file is natural language the agent loads and acts on, sometimes with executable scripts beside it. Nothing sandboxes the words. So the question is never only what a skill says it does. It is what the file can reach, who can change it, and when it gets loaded.
Injection through a skill is a supply chain problem.
A prompt is one message and then it is gone. A skill is a file that sits in your agent's skills directory and gets loaded, without you asking, every time its description matches what you are doing. Instructions written for the agent rather than for you keep working after the session that installed them ends, after the upstream repository changes, and on every machine the file is synced to.
That is the shape of a dependency, so the questions are dependency questions. Where did this come from. What does it touch. What changed since the last time somebody read it.
Capabilities, not verdicts.
The capability scan reads a skill line by line and records which patterns matched, with the line
number and the matching line. It is deliberately blunt. The same function produces the flags on a
skill page and the flags npx skillmds scan prints in your terminal, and it is open
source, so you can read the rules instead of trusting a summary of them.
It does not decide whether a skill is safe. It tells you which lines to read.
What each flag means
Five flags. The first one is the absence of the other four. Each entry below lists what actually triggers it, what it tells you, and what to do about it.
-
docs_onlyDocumentation only
- Triggered by
- No other pattern matched anywhere in the body. It is the fallback result, not a rule of its own.
- What it means
- The skill is prose. It tells the agent what to do in words, and nothing in it looks like a command, a URL, or a credential.
- What to do
- Read it anyway. Prose is exactly where instructions aimed at the agent rather than at you would live, and no pattern will catch those.
-
executes_scriptsExecutes scripts
- Triggered by
- A fenced code block tagged sh, bash, python, py, js, ts, ruby or rb, or the tokens subprocess, os.system, child_process or exec(
- What it means
- The instructions contain commands or code that an agent may run on your machine, with whatever access you have.
- What to do
- Read the commands, not the description. A skill that runs things is normal. A command nobody read is the problem.
-
network_callsMakes network calls
- Triggered by
- fetch, requests., urllib, axios, curl, wget, websocket, or any http:// or https:// URL
- What it means
- Something in the skill points at a remote host, either to pull something down or to send something out.
- What to do
- Look at which hosts, and in which direction. Fetching a public specification is not the same shape as posting your working directory somewhere.
-
reads_secretsReads secrets
- Triggered by
- api_key, api-key, apikey, secret, token, password, os.environ, process.env or getenv
- What it means
- Credentials are in scope somewhere in the text.
- What to do
- Read this one together with the network flag. A skill that reads a credential to use it locally and a skill that reads a credential and then calls out carry the same flag and are very different files.
-
untrusted_installInstalls from an untrusted source
- Triggered by
- Fetch-and-execute patterns: a custom npm registry (--registry=, npm config set registry), a custom pip index (--index-url, --extra-index-url), curl or wget piped into a shell, a PowerShell request piped into iex, bash process substitution around a download, or an archive installed straight from a URL that is not the official npm or PyPI host.
- What it means
- The skill installs software from somewhere you did not choose, so the code your agent ends up running is decided by whoever controls that source.
- What to do
- This is the one to stop on and read line by line. Pinning a version is no protection when the registry itself is what got substituted.
Where these flags are wrong
The scan is pattern matching over single lines. It has no idea what a skill intends, and it produces false positives constantly, by design:
- A fenced bash block inside documentation sets
executes_scripts, even when the skill is only showing you a command to copy. - Any
https://URL setsnetwork_calls, including a link to a specification in a footnote. - The word
tokenin ordinary prose setsreads_secrets. A skill about tokenizers carries that flag with no credential anywhere in it.
Read a flag as a pointer to a line, never as a judgement about a file. It is also why the registry publishes the flags themselves rather than a grade computed from them. A grade would hide the one part that is actually useful, which is where to look.
The same scanner runs locally, and running it yourself is the point. Point it at a skill you are about to install, or at a whole repository, and you get every flag with the line and the snippet that triggered it. The command is at the bottom of this page.
What SkillMD publishes, and on how much of it
Measured against the registry database on 2026-09-17. Every share below uses one denominator, the 860,246 public skills in the registry on that date.
- 860,246 public skills. The denominator for everything else on this page.
- 100% of those 860,246 carry a quality score derived from the open-source lint rules.
- 51.9% 446,611 of 860,246 carry stored capability flags.
- 4.5% 39,078 of 860,246 carry a stored result from an independent third-party scanner.
SkillMD does not claim corpus-wide scanning. Most of this registry was indexed from public repositories rather than published through a submission flow, and scanner coverage did not grow at the speed the index did. The capability scan is deterministic, needs no model call, and runs in well under a second on one file, so the gap is one you can close yourself on any skill you care about before you install it.
Two scanners that are not ours
Both are open source, both are published by companies with no stake in how this registry looks, and both verdicts appear on the skills that have them. As far as we know, no other public skill registry publishes third-party scanner results at all.
SkillSpector
by NVIDIA
Checks a skill against 68 vulnerability patterns across 17 categories, including prompt injection, data exfiltration, privilege escalation and supply chain patterns, and reports a 0 to 100 risk score with an overall severity.
Skill Scanner
by Cisco AI Defense
Layers signature rules, YARA and behavioral dataflow analysis over the skill and its bundled files to find prompt injection, data exfiltration and malicious code, and reports a result with a maximum finding severity.
Both report on the same five-tier scale, so the results are comparable: pass, caution, warning, fail, inconclusive. When two scanners disagree about a skill, the disagreement stays visible instead of being averaged away, and it is usually the fastest signal that a file is worth reading in full.
The research this page stands on
The people doing the primary work on skill security are publishing it openly. If you are setting policy for a team, read these before you read any registry's marketing, including ours.
- ToxicSkills Snyk
Analysed 3,984 agent skills, which the authors described as the largest publicly available corpus of agent skills then known, and reported the malicious and unsafe patterns found in it.
- The Next AI Supply Chain Risk: Malicious Skills in Agentic AI HiddenLayer
Frames skills as a software supply chain surface and walks through how a malicious skill reaches an agent and what it can reach once it is there.
- Research note: SKILL.md agent context poisoning Cloud Security Alliance Labs
An industry-body note on poisoning an agent's context through the skill file itself, written for the people who have to approve this kind of thing in an enterprise.
- AI agent skills: the new standard for modular AI workflows Backslash Security
A vendor overview of the skill format and the security questions that follow from making instructions installable.
- “Do Not Mention This to the User”: Malicious Agent Skills in the Wild arXiv preprint
Measurement work on skills published in public ecosystems, including instructions written to be hidden from the person the agent is working for.
- How Your Credentials Are Leaked by LLM Agent Skills arXiv preprint
Traces the paths by which a skill can move a credential out of the environment it was meant to stay in, which is the concrete version of the reads_secrets question.
Working on agent skill supply chain security and want corpus data, per-file hashes, or scan output across a set of skills? Write to hi@skillmd.com.
Check a skill yourself
Nothing on this page has to be taken on trust. Both commands accept a local path or a GitHub source, and neither one sends your file anywhere.
npx skillmds@latest lint .
Validates SKILL.md against the format spec and prints the quality score, the same score the registry stores.
npx skillmds@latest scan .
Prints every capability flag with the line number and the line that matched it.
$ npx skillmds@latest scan ./my-skill
OK ./my-skill/SKILL.md network_calls, reads_secrets
network_calls :9 See the spec at https://agentskills.io
reads_secrets :21 Put your API token in the environment
Add --deny executes_scripts, or any other flag name, to make the scan exit non-zero,
which is enough to gate a pull request that adds a skill to a repository. Both commands come from
@skillmds/core,
which is MIT licensed, so the rule behind every flag on this site is readable, forkable and testable
against your own corpus.
Questions
Can an AI agent skill be malicious?
Yes. A skill is natural-language instructions that an agent follows using your own permissions, and it can ship scripts alongside them. Published research has found skills carrying instructions written to be hidden from the user, and skills that move credentials out of the environment. Read a skill before you install it, and read the diff before you update it.
What is prompt injection through an agent skill?
It is instructions inside the skill body that address the agent rather than the reader. What makes it a supply chain problem rather than one bad message is persistence: once the file is installed, the agent loads it as trusted guidance every time a request matches its description, on every machine the file is synced to, until someone removes it.
Does a capability flag mean a skill is unsafe?
No. Flags describe what a skill's text touches, not whether it should be trusted. The scan is pattern matching over lines, so a fenced bash block inside documentation sets the executes-scripts flag, any https:// URL sets the network-calls flag, and the word token in ordinary prose sets the reads-secrets flag. Use the flags to decide which lines to read.
How many skills on SkillMD have been scanned?
As of 2026-09-17 the registry holds 860,246 public skills. All 860,246 carry a quality score derived from the open-source lint rules. 446,611 of 860,246 (51.9%) carry stored capability flags, and 39,078 of 860,246 (4.5%) carry a stored result from an independent third-party scanner. SkillMD does not claim corpus-wide scanning.
Which independent security scanners does SkillMD run?
NVIDIA SkillSpector, which checks 68 vulnerability patterns across 17 categories and reports a 0 to 100 risk score, and Cisco AI Defense Skill Scanner, which combines signature rules, YARA and behavioral dataflow analysis. Both verdicts are published on the skills that have them, and each scanner has its own page at skillmd.com/auditors/skillspector and skillmd.com/auditors/skill-scanner.
How do I check a skill myself?
Run npx skillmds@latest scan on a local path or a GitHub source. It prints every flag with the line number and the matching line, so you can see exactly what triggered it. Add the deny option with a flag name to make it exit non-zero in CI. The scanner is the scanSecurity function in the MIT-licensed @skillmds/core package, so the flags on this site are reproducible from source.
New to the format? Start with what AI skills are, then the SKILL.md spec. Browsing with security in mind? Every skill page lists the capability flags and any scanner results it has.