An agent skill is a folder with a SKILL.md file in it: a name, a one-line description, and instructions an agent follows when the task matches, plus any scripts or reference files it needs. Anthropic introduced them on 16 October 2025 as "folders that include instructions, scripts, and resources that Claude can load when needed". The trick is progressive disclosure, which Anthropic's engineers call the core design principle: only the name and description sit in the agent's context, and the rest loads when the skill is used. That makes a skill cheap to install and easy to write. It's Markdown, not a protocol.
A year later skills are an open standard read by almost every coding agent, a registry with more than a million entries, a distribution channel for developer-tool companies, and a new software supply chain with the problems that come with one. This post puts the year's data together. One caveat runs through all of it: almost every number comes from someone with a stake. Vercel runs the biggest registry and counts its installs, the security figures come mostly from companies that sell scanning, and Anthropic and OpenAI sell the agents. We name the source and what it sells next to each figure, and we lean on the academic studies where we can.
Key findings
- 1The standard spread in about three months. After Anthropic made it an open standard on 18 December 2025, Copilot, Codex, Gemini CLI, VS Code and Cursor all shipped support by 22 January 2026. The agentskills.io showcase lists 46 products in early October 2026, but Anthropic still runs the spec.
- 2The registry is huge and top-heavy. Vercel, which runs skills.sh, says it reached one million skills and nearly 280 million installs in seven months, with 375 skills taking 62% of installs and nearly half installed exactly once.
- 3A handful of authors lead. Vercel's own
find-skillshas 3.7M installs, 7 of the top 10 skills are Matt Pocock's, and Jesse Vincent's superpowers is the 12th most-starred repository on GitHub. - 4People use them. In OpenAI's own paper, the share of weekly active Codex users invoking a skill rose from 5.4% on 1 March 2026 to 26.6% on 11 June.
- 5Skills help when they fire, and they often don't. Curated skills added 16.2 points to pass rates in SkillsBench, self-written ones didn't help, and in Vercel's evals the skill was never invoked in 56% of cases.
- 6Skills and MCP are complements, not rivals. A skill costs about 100 tokens until it's used, against about 26K for GitHub's MCP tools, but in Supabase's eval MCP plus a skill beat MCP alone for all four agent and model pairs, and MCP keeps growing.
- 7Security is the cost. An academic study found at least one vulnerability in 26.1% of 31,132 marketplace skills, a trojanized family on skills.sh reached 1.7M installs, and Trail of Bits got past every scanner it tried.
- 8Skills became a way to ship a product. 20+ developer-tool companies serve a skill index from
/.well-known/on their own domain, and Mintlify says agents were 66% of traffic to the docs it hosts in August.
46
Products on the Agent Skills client showcase, Oct 2026
Listings reviewed by Anthropic
Source: agentskills.io
3.7M
Installs of find-skills, the most-installed skill, early Oct 2026
Installs, not people
Source: skills.sh
26.6%
Weekly active Codex users who invoked a skill, 11 Jun 2026, up from 5.4%
Source: OpenAI authors, arXiv
20+
Vendor domains serving a /.well-known skill index, early Oct 2026
Source: host0 probe
The standard and who adopted it#
Skills shipped on 16 October 2025 across the Claude apps, the API and Claude Code, whose 2.0.20 changelog reads "Added support for Claude Skills". The format was simple enough to copy, and others did before anyone asked them to. A Codex feature request for SKILL.md support opened four days after launch, Codex CLI merged experimental support in early December, and Simon Willison found a /home/oai/skills folder inside ChatGPT's Code Interpreter on 12 December.
On 18 December Anthropic published Agent Skills as an open standard at agentskills.io. GitHub shipped skills in Copilot the same day, with a line that explains how the standard spread: "If you've already set up skills for Claude Code in the .claude/skills directory… Copilot will pick them up automatically." Amp says it reads .claude/skills "for compatibility with existing skills", and Goose's v1.16.0 lists "claude compatibility". Reading the folder a user already had was the cheapest way to support skills, so nearly everyone did.
Who shipped SKILL.md support, and when
First release with Agent Skills support, from each vendor's changelog, Oct 2025 to Sep 2026
16 Oct 2025
16 Oct 2025
Anthropic launches Agent Skills
Claude apps, Claude Code 2.0.20 and the API.Source: Anthropic
2 Dec 2025
2 Dec 2025
Codex CLI: experimental skills
Merged as an experimental feature for internal testing.Source: GitHub
10 Dec 2025
18 Dec 2025
18 Dec 2025
Open standard; GitHub Copilot ships skills
agentskills.io goes up; Copilot reads .claude/skills.Source: GitHub changelog
19 Dec 2025
19 Dec 2025
Codex follows the open spec
Following the open spec, "a skill is a folder with a required SKILL.md".Source: OpenAI
22 Dec 2025
7 Jan 2026
8 Jan 2026
16 Jan 2026
20 Jan 2026
22 Jan 2026
6 Mar 2026
22 Apr 2026
22 Apr 2026
Google's official skills repository
Launched at Cloud Next with thirteen skills.Source: Google Cloud
6 Aug 2026
6 Aug 2026
Agent Plugins 1.0
A package format for skills and MCP servers from Amazon, Cursor, Microsoft, OpenAI and Vercel.Source: AAIF blog
23 Sep 2026
The spec itself is small. agentskills.io requires two fields, a name of up to 64 characters and a description of up to 1,024, and it suggests a budget: about 100 tokens of metadata loaded at startup, under 5,000 tokens of instructions loaded when the skill is activated, and a SKILL.md under 500 lines. Everything else (scripts, references, assets) loads only when needed.
The governance is less settled. On 9 December 2025 MCP and AGENTS.md went to the Linux Foundation's new Agentic AI Foundation, but Agent Skills is not on its project list. The spec repository's contributing guide still says "Logo requests are reviewed by the Anthropic team", and Anthropic reviews the showcase listings. Even Agent Plugins 1.0, the packaging spec built on top of skills, says it "is not an AAIF project".
How big the ecosystem got#
Vercel launched skills.sh and the npx skills CLI on 20 January 2026, and it became the default registry. On 25 September Vercel said that "in seven months, the skills.sh registry grew to one million agent skills and recorded nearly 280 million installs". Those are Vercel's numbers about its own registry, counted by its own telemetry, and Vercel says the installs "do not represent unique people or necessarily independent choices."
Months to reach one million listings
Months from launch to 1M items, as compared by Vercel, Sep 2026
| Label | Value |
|---|---|
| skills.sh skills | 7 months |
| GitHub repositories | 27 months |
| App Store apps | 63 months |
| npm packages | 117 months |
Source: Vercel, State of agent skills
The registry's live counter is not a clean growth line. It sat around 91,000 from late March to mid-May, jumped to 609,966 by 31 May (more likely a change in what's indexed than a publishing boom), and read 1,548,375 in a 2 October Wayback snapshot. Nobody has explained the jump. The safe statement is that Vercel reported one million skills on 25 September.
Installs of the most popular skill tell a steadier story. find-skills is Vercel's own skill: it searches the registry and installs other skills, so it sits at the front door of everything else.
Installs of the most-installed skill on skills.sh
All-time installs of the #1 skill on the leaderboard, Wayback snapshots and live, Jan to Oct 2026
| x | y |
|---|---|
| 27 Jan 2026 | 52K |
| 3 Feb 2026 | 87.6K |
| 10 Feb 2026 | 167.4K |
| 23 Feb 2026 | 300.8K |
| 1 Mar 2026 | 361.6K |
| 14 Mar 2026 | 544.9K |
| 31 Mar 2026 | 787.5K |
| 26 Apr 2026 | 1.2M |
| 13 May 2026 | 1.5M |
| 25 May 2026 | 1.5M |
| 31 May 2026 | 1.8M |
| 15 Jun 2026 | 2M |
| 5 Jul 2026 | 2.3M |
| 23 Jul 2026 | 2.6M |
| 5 Aug 2026 | 2.8M |
| 24 Aug 2026 | 3.1M |
| 14 Sep 2026 | 3.4M |
| 2 Oct 2026 | 3.7M |
Sources: skills.sh; Wayback Machine
Vercel's concentration numbers are the most useful thing in its report. "375 skills, or 0.04% of the registry, account for 62% of installs, and the top 1.2% account for 94% of installs", and "nearly half of all skills were installed exactly once." A registry of a million skills is, in practice, a few hundred skills people use and a long tail of experiments, forks and copies.
Outside skills.sh the count is bigger, and it measures something else. SkillsMP, which crawls public GitHub for SKILL.md files, counted more than 3.3 million in early October. That includes forks and vendored copies, so it counts files rather than distinct skills, but it shows how fast the format spread into repositories.
SKILL.md files collected from public GitHub
SkillsMP's count of collected SKILL.md files, Dec 2025 to Oct 2026
| x | y |
|---|---|
| 5 Dec 2025 | 20.1K |
| 19 Feb 2026 | 239.7K |
| 5 Mar 2026 | 364.2K |
| 9 Jun 2026 | 1.6M |
| 21 Jul 2026 | 2.3M |
| 2 Sep 2026 | 2.9M |
| 3 Oct 2026 | 3.3M |
Sources: SkillsMP; Wayback Machine
The CLI's download count is the third measure, and the noisiest. The skills package on npm was downloaded about 24.7 million times in the 30 days to early October, and about 168 million times in 2026, per the npm API. Every npx skills run counts as a download, and the find-skills skill tells agents to run the CLI themselves, so these are CLI runs, not users.
Monthly downloads of the skills CLI on npm
Downloads of the skills package per calendar month, Jan to Sep 2026
| x | y |
|---|---|
| Jan 2026 | 241K |
| Feb 2026 | 988.8K |
| Mar 2026 | 2.6M |
| Apr 2026 | 3M |
| May 2026 | 4.8M |
| Jun 2026 | 38.9M |
| Jul 2026 | 47.5M (47.5M peak) |
| Aug 2026 | 39.9M |
| Sep 2026 | 27.5M |
Source: npm downloads API
What people install#
The top of the leaderboard belongs to one skill that installs the others and one author's collection. Seven of the ten most-installed skills on skills.sh come from Matt Pocock's mattpocock/skills.
The ten most-installed skills on skills.sh
All-time installs per skill on the live leaderboard, early Oct 2026
| Label | Value |
|---|---|
| find-skills | 3.7M (vercel-labs/skills) |
| grill-me | 1.3M (mattpocock/skills) |
| grill-with-docs | 1.1M (mattpocock/skills) |
| improve-codebase-architecture | 1.1M (mattpocock/skills) |
| agent-browser | 1M (vercel-labs/agent-browser) |
| tdd | 1M (mattpocock/skills) |
| frontend-design | 956.6K (anthropics/skills) |
| setup-matt-pocock-skills | 947.3K (mattpocock/skills) |
| handoff | 925.8K (mattpocock/skills) |
| triage | 894.7K (mattpocock/skills) |
Source: skills.sh leaderboard
Install counts are easy to inflate. Just below the top ten, a reddit-automation skill from a repository created on 12 August, with about a dozen GitHub stars, had 812,125 installs and sat at #14. More than 21 Lark skills from open.feishu.cn each show about 745,000 installs, which looks like one bundle install counted many times. That's the same counter the trojanized skills below used to look popular.
GitHub stars are a different signal, harder to fake at scale and slower to move. Two individuals' repositories lead every vendor's: obra/superpowers, Jesse Vincent's skills framework, had 295,951 stars in early October, which makes it the 12th most-starred repository on GitHub, and Matt Pocock's collection had 277,896, eight months after it was created.
The most-starred skill repositories on GitHub
GitHub stars per repository, read from the GitHub API in early Oct 2026
| Label | Value |
|---|---|
| obra/superpowers | 296K (Jesse Vincent) |
| mattpocock/skills | 277.9K (Matt Pocock) |
| anthropics/skills | 179.9K (Anthropic, official) |
| ComposioHQ/awesome-claude-skills | 76.6K (a list) |
| heygen-com/hyperframes | 57.8K (video skills) |
| coreyhaines31/marketingskills | 53.5K (marketing) |
| github/awesome-copilot | 39.7K (GitHub, official) |
| anthropics/claude-plugins-official | 37.5K (plugin marketplace) |
| vercel-labs/skills | 33.3K (the npx skills CLI) |
| vercel-labs/agent-skills | 32K (Vercel, official) |
| openai/skills | 27.9K (OpenAI, official) |
| agentskills/agentskills | 25.9K (the spec) |
| google/skills | 21K (Google, official) |
Source: GitHub API
The vendors' collections matter more than their star counts suggest, because they're how a company teaches agents to use its product. skills.sh's official makers page lists 1,164 skills from NVIDIA, 605 from Anthropic and 582 from Microsoft. Google's repository launched at Cloud Next on 22 April "starting off with thirteen skills".
Skills vs MCP#
Skills arrived a year after the Model Context Protocol, and the first argument was whether they replace it. The case for skills is context cost. Anthropic's docs put a skill's always-loaded cost at "~100 tokens per Skill", with its instructions loading only when it's triggered. An MCP server, by default, loads the full schema of every tool up front. Anthropic's advanced tool use post from November 2025 measured how much that costs.
Tokens loaded before the user asks anything
Approximate tokens of always-loaded context per skill or MCP server, Anthropic's measurements, Nov 2025
| Label | Value |
|---|---|
| One skill (name and description) | ~100 |
| Splunk MCP server | ~2K |
| Sentry MCP server | ~3K |
| Slack MCP server, 11 tools | ~21K |
| GitHub MCP server, 35 tools | ~26K |
| Five common servers, 58 tools | ~55K |
| Worst case Anthropic saw internally | 134K |
Sources: Anthropic, advanced tool use; Claude docs, Agent Skills
The MCP side answered by borrowing the idea. Anthropic's Tool Search defers tool definitions until they're needed, which it says gives "an 85% reduction" in tokens. Its code execution with MCP pattern goes further: in Anthropic's worked example, presenting MCP tools as code the agent reads on demand "reduces the token usage from 150,000 tokens to 2,000 tokens", a 98.7% saving. In August the protocol's maintainers put the same idea on the MCP roadmap.
Connecting to a server with a hundred tools means the model pays for that entire surface before the user has asked a single question.
Skills have a budget too. Claude Code's docs say its skill listing is capped at 1% of the model's context window, with each entry cut at 1,536 characters, and when the listing overflows it drops descriptions, starting with the skills used least. Install enough skills and you get the MCP problem back, in a smaller form.
MCP isn't shrinking. Its maintainers reported "close to half-a-billion downloads a month" across the main SDKs in July, and the official MCP Registry held about 40,100 server names when we crawled it in early October. That's names, not working servers, and about 15% come from four bulk publishers.
The natural split is that the skill says how to do something well and the MCP server reaches live account data and takes actions. Supabase, which ships both, measured what the pair is worth.
Supabase's eval: MCP alone vs MCP plus a skill
Share of Supabase tasks scored as passing, by agent and model, Apr 2026
Source: Supabase
Nobody has published a skill-only arm on the same tasks, so "skill vs MCP" is still unmeasured. "Skill plus MCP vs MCP" is, and the pair wins.
Do skills work#
The best first-party usage number comes from OpenAI, which has an obvious interest in it. Its researchers' paper on Codex reports that "the share of active Codex users invoking any skill rose from 5.4% on March 1, 2026 to 26.6% on June 11, 2026", and that "within OpenAI, skill use is nearly universal: 96.2%". Anthropic hasn't published a comparable number for Claude, and no 2026 developer survey we found asks about skills.
Codex users who invoked a skill
Share of weekly active Codex users invoking any skill, Mar to Jun 2026
| Label | Value |
|---|---|
| All users, 1 Mar 2026 | 5.4% |
| All users, 11 Jun 2026 | 26.6% |
| Individual plans, 11 Jun | 25.7% |
| Organizational plans, 11 Jun | 30.4% |
| Inside OpenAI, 11 Jun | 96.2% |
Whether they make agents better is a different question, and the academic answer is "the good ones do". SkillsBench found in February that curated skills "raise average pass rate by 16.2 percentage points", from +4.5 points in software engineering to +51.9 in healthcare, with 16 of 84 tasks getting worse. Skills the model wrote for itself "provide no benefit on average" (−1.3 points). The current version, from June, reports 33.9% → 50.5% with curated skills across 87 tasks and 18 configurations, and finds focused skills beat big bundles. SWE-Skills-Bench is gloomier for coding: "39 of 49 skills yield zero pass-rate improvement, and the average gain is only +1.2%".
The bigger practical problem is that a skill only helps if the agent loads it. Vercel tested this on Next.js 16 tasks in January and found that "in 56% of eval cases, the skill was never invoked".
Vercel's Next.js evals: a skill vs a docs index
Pass rate on Vercel's Next.js 16 agent evals, by setup, Jan 2026
| Label | Value |
|---|---|
| No docs | 53% |
| Skill, default | 53% |
| Skill, explicit instructions | 79% |
| AGENTS.md docs index | 100% |
Source: Vercel
Anthropic says the same about its own model. Its skill-creator skill warns that "Claude has a tendency to 'undertrigger' skills -- to not use them when they'd be useful", and ships a tool to rewrite descriptions so they match more requests. The description field, 1,024 characters at most, is what decides whether a skill does anything at all.
Security#
A skill is instructions an agent follows plus, often, scripts it runs with the user's permissions. Anthropic's launch engineering post warned that malicious skills may "direct Claude to exfiltrate data and take unintended actions", and its docs still say to "use Skills only from trusted sources". A year of research shows why.
What security studies of skill registries found
Studies of public skill registries, Jan to Aug 2026; each has its own denominator
Sources: Liu et al.; Liu et al., USENIX Security; The Hacker News; Antiy; Snyk; OpenClaw; Zenity Labs
The academic baseline is Liu et al., who collected 42,447 skills from two marketplaces in December 2025 and analyzed 31,132. They found that "26.1% of skills contain at least one vulnerability", data exfiltration in 13.3% and privilege escalation in 11.8%, and that skills bundling scripts were 2.12 times likelier to be vulnerable. Most of those are flaws rather than attacks; the paper put 5.2% at "high-severity patterns strongly suggesting malicious intent". The attacks are what grew in 2026.
The first big campaign hit ClawHub, the registry for the OpenClaw agent. In February The Hacker News reported that Koi Security audited all 2,857 skills on it and found 341 malicious, 335 of them from one campaign whose fake "prerequisite" step installed the Atomic macOS Stealer. Antiy CERT later counted 1,184 malicious packages in ClawHub's history, from 12 author IDs. Snyk, which sells scanning and audits skills.sh, sampled 3,984 skills across ClawHub and skills.sh: 1,467 (36.82%) had at least one flaw, 534 (13.4%) a critical one, and 76 carried malicious payloads, 8 of them still live when it published.
The mainstream registry was hit in July. Zenity Labs, which sells agent security, found a family of look-alike skills imitating Paperclip and Browser Use that were "trojanized on July 11" after being listed clean. By 2 August they had more than 1.7 million aggregate installs on skills.sh. Zenity notes that "these counters are not user-unique", and Vercel and GitHub removed the skills within 12 hours of its outreach.
The attack doesn't need a script. Skill-Inject, an academic benchmark of 202 injection-task pairs, found "up to 80% attack success rate with frontier models" from instructions hidden in skill files. The registries' response has mostly been scanning, which helps with known payloads and not with a well-written instruction.
How registries and platforms responded
Security measures for skills, Feb to Oct 2026
7 Feb 2026
17 Feb 2026
17 Feb 2026
skills.sh adds security audits
Gen, Socket and Snyk audit more than 60,000 skills; flagged skills are hidden.Source: Vercel
19 May 2026
19 May 2026
NVIDIA signs its verified skills
Scanned, and signed with OpenSSF Model Signing so a download can be checked.Source: NVIDIA
1 Jun 2026
1 Jun 2026
ClawScan publishes its verdicts
206 malicious and 25,504 suspicious of 67,453 skill versions.Source: OpenClaw
3 Jun 2026
3 Jun 2026
Trail of Bits bypasses the scanners
Recommends curated marketplaces instead.Source: Trail of Bits
6 Aug 2026
6 Aug 2026
Zenity: 1.7M installs of trojanized skills
Removed within 12 hours of the report.Source: Zenity Labs
1 Sep 2026
1 Sep 2026
AIR raises $50M to vet agent add-ons
It says it filters out about 27% of the skills and add-ons it finds online.Source: TechCrunch
2 Oct 2026
2 Oct 2026
Anthropic turns on skill scanning for Enterprise
On by default for Enterprise organizations that hadn't set it; a fail blocks the skill.Source: Claude Help Center
Anthropic's scanning, per its Help Center, only covers skills added after it's turned on; skills already in an organization aren't scanned.
Skills as distribution#
For developer-tool companies, skills became a way to reach customers through their agents. When we probed in early October, more than 20 vendor domains served a skill index at /.well-known/agent-skills/index.json or the older /.well-known/skills/ path, the convention proposed in a Cloudflare RFC whose current version adds a sha256 digest for every file. An agent can find a company's skills from its domain alone.
Skills served from vendors' own domains
Skills listed in each domain's /.well-known skill index, probed early Oct 2026
| Label | Value |
|---|---|
| Hugging Face | 25 |
| Render | 21 |
| Clerk | 20 |
| Cloudflare | 16 |
| Netlify | 14 |
| Stripe | 10 (old /skills/ path only) |
| Paddle | 10 |
| Vercel | 9 |
| Neon | 9 |
| LiveKit | 7 |
| ElevenLabs | 7 |
| Resend | 5 |
| Supabase | 2 |
| Fly.io | 2 |
Source: host0 probe of https://<domain>/.well-known/{agent-skills,skills}/index.json, early Oct 2026
Documentation hosts made it the default. Mintlify put a skill file at /.well-known/skills/default/skill.md on every docs site it hosts in January. The traffic followed: Mintlify, which sells docs hosting, says agents went from 20.8% of traffic to its docs in February to 66% in August, when it counted 257 million agent requests against 131 million human page loads, and that 83% of agent traffic came through Markdown pages, /llms.txt or agent skills.
The other channels are the install command and the marketplace. A GitHub code search in early October found about 41,600 README files containing npx skills add (an estimate; code search counts copies). Anthropic's Claude Marketplace opened on 23 September with "more than 2,000" connectors and plugins built on "MCP and Agent Skills". We found no paid first-party skill store at Anthropic, OpenAI or GitHub: Anthropic told VentureBeat in December that "there are no revenue-sharing arrangements at this time", and skills are included in paid Claude plans at no extra cost.
What this means if you build with AI#
Skills are the cheapest way to teach an agent how you work and how a product is meant to be used. The data points to a few habits.
- Read a skill before you install it. It's a Markdown file and maybe a script; read both. A skill runs with your agent's permissions, and the install counter told 1.7 million installers that a trojanized family was popular.
- Prefer official and vendor skills. Install from the company that makes the product, its GitHub organization or its own domain's
/.well-known/index, or write your own. Anthropic's own advice is to use skills you created yourself or got from Anthropic. - Don't treat a scan as a clean bill of health. Registry scanners can be beaten in under an hour. A pass means no known payload was found, not that the instructions are safe.
- Write descriptions that trigger. The description is the only part the agent sees until it decides to use the skill. Say what it does and when to use it, using the words people will type. Agents undertrigger skills, so test whether yours fires.
- Keep a docs index in AGENTS.md for what must always apply. In Vercel's evals an always-loaded 8KB index beat a skill the agent skipped. Use a skill for the occasional procedure and AGENTS.md for the rules of the repo.
- Curate, don't generate. Self-written skills gave no benefit on average in SkillsBench. A skill that captures what you actually learned beats one the model wrote from what it already knew.
- Keep skills small and few. Focused skills beat big bundles in SkillsBench, and Claude Code drops descriptions once the listing passes 1% of context. Uninstall what you don't use.
- Use a skill with MCP, not instead of it. The skill carries the how and the MCP server the live data. In Supabase's eval the pair beat MCP alone every time.
- If you build a developer tool, ship it as a skill. Put a
SKILL.mdin a public repo, serve an index from your domain's/.well-known/agent-skills/, and give people annpx skills addline. Agents are already the main readers of many docs sites.
host0 ships its deploy as a skill: an agent reads host0.ai/skill.md, runs publish.sh on a folder or file, and gets back a URL to share.
Methodology#
This post is built on a data pack we compiled in early October 2026. Five research agents worked in parallel, one per angle: the standard and its adoption timeline, ecosystem size and distribution, security, skills vs MCP, and skills in practice. We then spot-checked about 30 of the numbers the post leans on: we fetched each primary page live and pulled the exact sentence, and re-queried live sources (the GitHub and npm APIs, the skills.sh leaderboard, SkillsMP, the MCP Registry, Wayback snapshots and vendors' /.well-known/ indexes). Each claim carries a tier: verified against the primary source that day, confirmed by two or more independent outlets when the primary was gone, or single-sourced. Before publishing we re-opened every single-sourced page we cite and dropped anything it no longer said.
We left out several claims that circulate widely:
- "Snyk found 1,467 malicious skills." Snyk's 1,467 is skills with any flaw; 76 were malicious.
- "1.7 million people installed malware." Zenity says the counters aren't user-unique.
- An Anthropic skills marketplace with a 15% revenue share in May 2026. We found no Anthropic source; the real launch is the Claude Marketplace in September.
- Higher recounts of the ClawHub campaign, found only on aggregators.
- Any single skills.sh counter value as a growth rate, or npm downloads as users.
- A precise count of SKILL.md files on GitHub. Code-search totals are estimates and include copies.
- Details we couldn't re-confirm on the source page: the exact totals on skills.sh's official makers page and the date the Claude API took skills out of beta.
Limitations:
- Conflicts of interest run through almost everything. Vercel runs skills.sh, maintains the CLI, publishes the most-installed skill and counts the installs. Snyk, Socket, Gen, Zenity, Koi (now part of Palo Alto Networks), Antiy, Trail of Bits and AIR sell scanning, vetting or audits. Anthropic created the standard and sells Claude; OpenAI's researchers wrote the Codex paper about their own product; Supabase and Mintlify benefit from skills looking useful. Only Liu et al., SkillsBench, SWE-Skills-Bench and Skill-Inject have no product attached.
- Installs and downloads aren't people. Both are anonymous CLI telemetry, inflated by bundles and by agents running the CLI themselves.
- Denominators differ. The security studies sample different registries at different times; ClawHub figures describe one loosely moderated registry, not the ecosystem.
- Everything moves. Stars, installs and registry counts change by the hour; we give the date we read each one.
Open questions#
The public data leaves gaps:
- What happened to the skills.sh counter? It jumped from about 91,000 to 609,966 in May, and Vercel hasn't said why.
- How big is the top skill, really? Vercel says even the most-installed skill is "less than 1%" of installs, but 3.7 million
find-skillsinstalls is about 1.3% of 280 million. - How many people use skills? No registry publishes unique installers, and Anthropic has published no adoption number for Claude. OpenAI's Codex paper is the only first-party figure with a denominator.
- Does a skill alone beat MCP alone? Supabase compared MCP with MCP plus a skill; nobody has a skill-only arm on the same tasks.
- How much of skills.sh is flagged? Its three audit partners scan every skill, but there's no public total.
- Who will govern the standard? MCP and AGENTS.md went to a foundation; Agent Skills is still run by Anthropic.
- Will the spec adopt signing? NVIDIA signs its skills and the discovery RFC adds digests, but the spec has no security section.
We plan to come back to several of these with data of our own.
