Blog

/Research

State of agent skills 2026

46 clients read SKILL.md, skills.sh lists 1M+ skills and 26.6% of weekly Codex users run one, yet 26.1% of 31,132 skills had a vulnerability. A year of data.

·12 min read

Summarize in ChatGPT
State of agent skills 2026: a line of installs of the most-installed skill on skills.sh (find-skills since February) rising from 52K in January to 3.7M in October 2026, with four stats — 46 clients support SKILL.md, 1M+ skills on skills.sh, 26.6% of weekly Codex users used a skill, 26.1% of 31,132 skills had a vulnerability.
On this page

An agent skill is a folder with a SKILL.md file in it: a name, a one-line description, and instructions an agent follows when the task matches, plus any scripts or reference files it needs. Anthropic introduced them on 16 October 2025 as "folders that include instructions, scripts, and resources that Claude can load when needed". The trick is progressive disclosure, which Anthropic's engineers call the core design principle: only the name and description sit in the agent's context, and the rest loads when the skill is used. That makes a skill cheap to install and easy to write. It's Markdown, not a protocol.

A year later skills are an open standard read by almost every coding agent, a registry with more than a million entries, a distribution channel for developer-tool companies, and a new software supply chain with the problems that come with one. This post puts the year's data together. One caveat runs through all of it: almost every number comes from someone with a stake. Vercel runs the biggest registry and counts its installs, the security figures come mostly from companies that sell scanning, and Anthropic and OpenAI sell the agents. We name the source and what it sells next to each figure, and we lean on the academic studies where we can.

Key findings

  1. 1
    The standard spread in about three months. After Anthropic made it an open standard on 18 December 2025, Copilot, Codex, Gemini CLI, VS Code and Cursor all shipped support by 22 January 2026. The agentskills.io showcase lists 46 products in early October 2026, but Anthropic still runs the spec.
  2. 2
    The registry is huge and top-heavy. Vercel, which runs skills.sh, says it reached one million skills and nearly 280 million installs in seven months, with 375 skills taking 62% of installs and nearly half installed exactly once.
  3. 3
    A handful of authors lead. Vercel's own find-skills has 3.7M installs, 7 of the top 10 skills are Matt Pocock's, and Jesse Vincent's superpowers is the 12th most-starred repository on GitHub.
  4. 4
    People use them. In OpenAI's own paper, the share of weekly active Codex users invoking a skill rose from 5.4% on 1 March 2026 to 26.6% on 11 June.
  5. 5
    Skills help when they fire, and they often don't. Curated skills added 16.2 points to pass rates in SkillsBench, self-written ones didn't help, and in Vercel's evals the skill was never invoked in 56% of cases.
  6. 6
    Skills and MCP are complements, not rivals. A skill costs about 100 tokens until it's used, against about 26K for GitHub's MCP tools, but in Supabase's eval MCP plus a skill beat MCP alone for all four agent and model pairs, and MCP keeps growing.
  7. 7
    Security is the cost. An academic study found at least one vulnerability in 26.1% of 31,132 marketplace skills, a trojanized family on skills.sh reached 1.7M installs, and Trail of Bits got past every scanner it tried.
  8. 8
    Skills became a way to ship a product. 20+ developer-tool companies serve a skill index from /.well-known/ on their own domain, and Mintlify says agents were 66% of traffic to the docs it hosts in August.

46

Products on the Agent Skills client showcase, Oct 2026

Listings reviewed by Anthropic

Source: agentskills.io

1M+

Skills on skills.sh seven months after launch, Sep 2026

1.5M listed on 2 Oct

Source: Vercel

3.7M

Installs of find-skills, the most-installed skill, early Oct 2026

Installs, not people

Source: skills.sh

26.6%

Weekly active Codex users who invoked a skill, 11 Jun 2026, up from 5.4%

Source: OpenAI authors, arXiv

~100

Tokens a skill costs before it's used, vs ~26K for GitHub's MCP tools

Source: Anthropic

56%

Next.js eval cases where the skill was never invoked

Source: Vercel

26.1%

Marketplace skills with at least one vulnerability, of 31,132

Academic

Source: Liu et al., arXiv

20+

Vendor domains serving a /.well-known skill index, early Oct 2026

Source: host0 probe

The standard and who adopted it#

Skills shipped on 16 October 2025 across the Claude apps, the API and Claude Code, whose 2.0.20 changelog reads "Added support for Claude Skills". The format was simple enough to copy, and others did before anyone asked them to. A Codex feature request for SKILL.md support opened four days after launch, Codex CLI merged experimental support in early December, and Simon Willison found a /home/oai/skills folder inside ChatGPT's Code Interpreter on 12 December.

On 18 December Anthropic published Agent Skills as an open standard at agentskills.io. GitHub shipped skills in Copilot the same day, with a line that explains how the standard spread: "If you've already set up skills for Claude Code in the .claude/skills directory… Copilot will pick them up automatically." Amp says it reads .claude/skills "for compatibility with existing skills", and Goose's v1.16.0 lists "claude compatibility". Reading the folder a user already had was the cheapest way to support skills, so nearly everyone did.

Who shipped SKILL.md support, and when

First release with Agent Skills support, from each vendor's changelog, Oct 2025 to Sep 2026

  1. 16 Oct 2025

    Anthropic launches Agent Skills

    Claude apps, Claude Code 2.0.20 and the API.

    Source: Anthropic

  2. 2 Dec 2025

    Codex CLI: experimental skills

    Merged as an experimental feature for internal testing.

    Source: GitHub

  3. 10 Dec 2025

    Amp and Goose

    Both also read Claude's skill folders.

    Source: Amp

  4. 18 Dec 2025

    Open standard; GitHub Copilot ships skills

    agentskills.io goes up; Copilot reads .claude/skills.

    Source: GitHub changelog

  5. 19 Dec 2025

    Codex follows the open spec

    Following the open spec, "a skill is a folder with a required SKILL.md".

    Source: OpenAI

  6. 22 Dec 2025

    OpenCode

    Source: GitHub

  7. 7 Jan 2026

    Gemini CLI (preview builds)

    Source: GitHub

  8. 8 Jan 2026

    VS Code 1.108

    Behind a setting; reads .github/skills or .claude/skills.

    Source: VS Code

  9. 16 Jan 2026

    Kiro CLI 1.24

    Source: Kiro

  10. 20 Jan 2026

    skills.sh and npx skills launch

    Vercel's directory, leaderboard and CLI.

    Source: Vercel

  11. 22 Jan 2026

    Cursor 2.4

    In the editor and the CLI.

    Source: Cursor

  12. 6 Mar 2026

    ChatGPT Enterprise and Edu (beta)

    Source: OpenAI

  13. 22 Apr 2026

    Google's official skills repository

    Launched at Cloud Next with thirteen skills.

    Source: Google Cloud

  14. 6 Aug 2026

    Agent Plugins 1.0

    A package format for skills and MCP servers from Amazon, Cursor, Microsoft, OpenAI and Vercel.

    Source: AAIF blog

  15. 23 Sep 2026

    Claude Marketplace

    More than 2,000 connectors and plugins.

    Source: Anthropic

Every major coding agent shipped support within about three months of launch, most within five weeks of the open standard. Anthropic's competitors adopted its format rather than building their own.

The spec itself is small. agentskills.io requires two fields, a name of up to 64 characters and a description of up to 1,024, and it suggests a budget: about 100 tokens of metadata loaded at startup, under 5,000 tokens of instructions loaded when the skill is activated, and a SKILL.md under 500 lines. Everything else (scripts, references, assets) loads only when needed.

The governance is less settled. On 9 December 2025 MCP and AGENTS.md went to the Linux Foundation's new Agentic AI Foundation, but Agent Skills is not on its project list. The spec repository's contributing guide still says "Logo requests are reviewed by the Anthropic team", and Anthropic reviews the showcase listings. Even Agent Plugins 1.0, the packaging spec built on top of skills, says it "is not an AAIF project".

How big the ecosystem got#

Vercel launched skills.sh and the npx skills CLI on 20 January 2026, and it became the default registry. On 25 September Vercel said that "in seven months, the skills.sh registry grew to one million agent skills and recorded nearly 280 million installs". Those are Vercel's numbers about its own registry, counted by its own telemetry, and Vercel says the installs "do not represent unique people or necessarily independent choices."

Months to reach one million listings

Months from launch to 1M items, as compared by Vercel, Sep 2026

Months to reach one million listings
LabelValue
skills.sh skills7 months
GitHub repositories27 months
App Store apps63 months
npm packages117 months
Vercel's comparison, not ours. A skill is far cheaper to make than an app or a package, many listings are copies, and nearly half of all skills on skills.sh were installed exactly once.

Source: Vercel, State of agent skills

The registry's live counter is not a clean growth line. It sat around 91,000 from late March to mid-May, jumped to 609,966 by 31 May (more likely a change in what's indexed than a publishing boom), and read 1,548,375 in a 2 October Wayback snapshot. Nobody has explained the jump. The safe statement is that Vercel reported one million skills on 25 September.

Installs of the most popular skill tell a steadier story. find-skills is Vercel's own skill: it searches the registry and installs other skills, so it sits at the front door of everything else.

Installs of the most-installed skill on skills.sh

All-time installs of the #1 skill on the leaderboard, Wayback snapshots and live, Jan to Oct 2026

Installs of the most-installed skill on skills.sh
xy
27 Jan 202652K
3 Feb 202687.6K
10 Feb 2026167.4K
23 Feb 2026300.8K
1 Mar 2026361.6K
14 Mar 2026544.9K
31 Mar 2026787.5K
26 Apr 20261.2M
13 May 20261.5M
25 May 20261.5M
31 May 20261.8M
15 Jun 20262M
5 Jul 20262.3M
23 Jul 20262.6M
5 Aug 20262.8M
24 Aug 20263.1M
14 Sep 20263.4M
2 Oct 20263.7M
On 27 January the top skill was vercel-react-best-practices; find-skills has been #1 in every snapshot since 3 February. The line roughly tripled between late April and October. Installs are anonymous CLI events, not people.

Sources: skills.sh; Wayback Machine

Vercel's concentration numbers are the most useful thing in its report. "375 skills, or 0.04% of the registry, account for 62% of installs, and the top 1.2% account for 94% of installs", and "nearly half of all skills were installed exactly once." A registry of a million skills is, in practice, a few hundred skills people use and a long tail of experiments, forks and copies.

Outside skills.sh the count is bigger, and it measures something else. SkillsMP, which crawls public GitHub for SKILL.md files, counted more than 3.3 million in early October. That includes forks and vendored copies, so it counts files rather than distinct skills, but it shows how fast the format spread into repositories.

SKILL.md files collected from public GitHub

SkillsMP's count of collected SKILL.md files, Dec 2025 to Oct 2026

SKILL.md files collected from public GitHub
xy
5 Dec 202520.1K
19 Feb 2026239.7K
5 Mar 2026364.2K
9 Jun 20261.6M
21 Jul 20262.3M
2 Sep 20262.9M
3 Oct 20263.3M
About 170 times more files in ten months. Forks and copies count, so read this as how widely SKILL.md files are checked in, not how many distinct skills exist.

Sources: SkillsMP; Wayback Machine

The CLI's download count is the third measure, and the noisiest. The skills package on npm was downloaded about 24.7 million times in the 30 days to early October, and about 168 million times in 2026, per the npm API. Every npx skills run counts as a download, and the find-skills skill tells agents to run the CLI themselves, so these are CLI runs, not users.

Monthly downloads of the skills CLI on npm

Downloads of the skills package per calendar month, Jan to Sep 2026

Monthly downloads of the skills CLI on npm
xy
Jan 2026241K
Feb 2026988.8K
Mar 20262.6M
Apr 20263M
May 20264.8M
Jun 202638.9M
Jul 202647.5M (47.5M peak)
Aug 202639.9M
Sep 202627.5M
The eightfold step in June has no public explanation and no matching jump in skills.sh install counts, so treat it as a change in how often the CLI runs, not a wave of new people. October is left out: only five days of it had passed.

Source: npm downloads API

What people install#

The top of the leaderboard belongs to one skill that installs the others and one author's collection. Seven of the ten most-installed skills on skills.sh come from Matt Pocock's mattpocock/skills.

The ten most-installed skills on skills.sh

All-time installs per skill on the live leaderboard, early Oct 2026

The ten most-installed skills on skills.sh
LabelValue
find-skills3.7M (vercel-labs/skills)
grill-me1.3M (mattpocock/skills)
grill-with-docs1.1M (mattpocock/skills)
improve-codebase-architecture1.1M (mattpocock/skills)
agent-browser1M (vercel-labs/agent-browser)
tdd1M (mattpocock/skills)
frontend-design956.6K (anthropics/skills)
setup-matt-pocock-skills947.3K (mattpocock/skills)
handoff925.8K (mattpocock/skills)
triage894.7K (mattpocock/skills)
The highlighted bars are Matt Pocock's skills: seven of the top ten. The other three come from Vercel, which runs the registry, and Anthropic. Installs are CLI events, and installing a collection counts each skill in it.

Source: skills.sh leaderboard

Install counts are easy to inflate. Just below the top ten, a reddit-automation skill from a repository created on 12 August, with about a dozen GitHub stars, had 812,125 installs and sat at #14. More than 21 Lark skills from open.feishu.cn each show about 745,000 installs, which looks like one bundle install counted many times. That's the same counter the trojanized skills below used to look popular.

GitHub stars are a different signal, harder to fake at scale and slower to move. Two individuals' repositories lead every vendor's: obra/superpowers, Jesse Vincent's skills framework, had 295,951 stars in early October, which makes it the 12th most-starred repository on GitHub, and Matt Pocock's collection had 277,896, eight months after it was created.

The most-starred skill repositories on GitHub

GitHub stars per repository, read from the GitHub API in early Oct 2026

The most-starred skill repositories on GitHub
LabelValue
obra/superpowers296K (Jesse Vincent)
mattpocock/skills277.9K (Matt Pocock)
anthropics/skills179.9K (Anthropic, official)
ComposioHQ/awesome-claude-skills76.6K (a list)
heygen-com/hyperframes57.8K (video skills)
coreyhaines31/​marketingskills53.5K (marketing)
github/awesome-copilot39.7K (GitHub, official)
anthropics/claude-plugins-official37.5K (plugin marketplace)
vercel-labs/skills33.3K (the npx skills CLI)
vercel-labs/agent-skills32K (Vercel, official)
openai/skills27.9K (OpenAI, official)
agentskills/agentskills25.9K (the spec)
google/skills21K (Google, official)
The highlighted bars are the vendors' official skill collections. Two people's ways of working out-star all of them; Anthropic's own repository is the only official one within reach.

Source: GitHub API

The vendors' collections matter more than their star counts suggest, because they're how a company teaches agents to use its product. skills.sh's official makers page lists 1,164 skills from NVIDIA, 605 from Anthropic and 582 from Microsoft. Google's repository launched at Cloud Next on 22 April "starting off with thirteen skills".

Skills vs MCP#

Skills arrived a year after the Model Context Protocol, and the first argument was whether they replace it. The case for skills is context cost. Anthropic's docs put a skill's always-loaded cost at "~100 tokens per Skill", with its instructions loading only when it's triggered. An MCP server, by default, loads the full schema of every tool up front. Anthropic's advanced tool use post from November 2025 measured how much that costs.

Tokens loaded before the user asks anything

Approximate tokens of always-loaded context per skill or MCP server, Anthropic's measurements, Nov 2025

Tokens loaded before the user asks anything
LabelValue
One skill (name and description)~100
Splunk MCP server~2K
Sentry MCP server~3K
Slack MCP server, 11 tools~21K
GitHub MCP server, 35 tools~26K
Five common servers, 58 tools~55K
Worst case Anthropic saw internally134K
The highlighted bar, one skill, is a sliver at this scale: a skill costs a few hundred times less than one large MCP server until it's used. The spread between servers is about how verbose their schemas are, not MCP itself.

Sources: Anthropic, advanced tool use; Claude docs, Agent Skills

The MCP side answered by borrowing the idea. Anthropic's Tool Search defers tool definitions until they're needed, which it says gives "an 85% reduction" in tokens. Its code execution with MCP pattern goes further: in Anthropic's worked example, presenting MCP tools as code the agent reads on demand "reduces the token usage from 150,000 tokens to 2,000 tokens", a 98.7% saving. In August the protocol's maintainers put the same idea on the MCP roadmap.

Connecting to a server with a hundred tools means the model pays for that entire surface before the user has asked a single question.

— MCP lead maintainers, The new MCP roadmap, 22 Aug 2026

Skills have a budget too. Claude Code's docs say its skill listing is capped at 1% of the model's context window, with each entry cut at 1,536 characters, and when the listing overflows it drops descriptions, starting with the skills used least. Install enough skills and you get the MCP problem back, in a smaller form.

MCP isn't shrinking. Its maintainers reported "close to half-a-billion downloads a month" across the main SDKs in July, and the official MCP Registry held about 40,100 server names when we crawled it in early October. That's names, not working servers, and about 15% come from four bulk publishers.

The natural split is that the skill says how to do something well and the MCP server reaches live account data and takes actions. Supabase, which ships both, measured what the pair is worth.

Supabase's eval: MCP alone vs MCP plus a skill

Share of Supabase tasks scored as passing, by agent and model, Apr 2026

Agent (model)BaselineMCP onlyMCP + skill
Claude Code (Opus 4.6)58%50%67%
Claude Code (Sonnet 4.6)46%58%71%
Codex (GPT-5.4)71%71%88%
Codex (GPT-5.4 Mini)42%63%71%
MCP plus the skill scored highest for every pair. MCP alone didn't always help: for Claude Code with Opus 4.6 it scored below the baseline. Supabase ships both, and an LLM judge scored six scenarios per condition.

Source: Supabase

Nobody has published a skill-only arm on the same tasks, so "skill vs MCP" is still unmeasured. "Skill plus MCP vs MCP" is, and the pair wins.

Do skills work#

The best first-party usage number comes from OpenAI, which has an obvious interest in it. Its researchers' paper on Codex reports that "the share of active Codex users invoking any skill rose from 5.4% on March 1, 2026 to 26.6% on June 11, 2026", and that "within OpenAI, skill use is nearly universal: 96.2%". Anthropic hasn't published a comparable number for Claude, and no 2026 developer survey we found asks about skills.

Codex users who invoked a skill

Share of weekly active Codex users invoking any skill, Mar to Jun 2026

Codex users who invoked a skill
LabelValue
All users, 1 Mar 20265.4%
All users, 11 Jun 202626.6%
Individual plans, 11 Jun25.7%
Organizational plans, 11 Jun30.4%
Inside OpenAI, 11 Jun96.2%
Use roughly quintupled in about three months. Organizations use skills a little more than individuals, and OpenAI's own staff almost all do. The paper is by OpenAI authors about OpenAI's product.

Source: The Shift to Agentic AI: Evidence from Codex, arXiv

Whether they make agents better is a different question, and the academic answer is "the good ones do". SkillsBench found in February that curated skills "raise average pass rate by 16.2 percentage points", from +4.5 points in software engineering to +51.9 in healthcare, with 16 of 84 tasks getting worse. Skills the model wrote for itself "provide no benefit on average" (−1.3 points). The current version, from June, reports 33.9% → 50.5% with curated skills across 87 tasks and 18 configurations, and finds focused skills beat big bundles. SWE-Skills-Bench is gloomier for coding: "39 of 49 skills yield zero pass-rate improvement, and the average gain is only +1.2%".

The bigger practical problem is that a skill only helps if the agent loads it. Vercel tested this on Next.js 16 tasks in January and found that "in 56% of eval cases, the skill was never invoked".

Vercel's Next.js evals: a skill vs a docs index

Pass rate on Vercel's Next.js 16 agent evals, by setup, Jan 2026

Vercel's Next.js evals: a skill vs a docs index
LabelValue
No docs53%
Skill, default53%
Skill, explicit instructions79%
AGENTS.md docs index100%
With default settings the skill added nothing, because the agent mostly didn't call it. Telling it to use the skill helped; a compressed 8KB docs index in AGENTS.md, which the agent always sees, scored 100%. Vercel runs skills.sh.

Source: Vercel

Anthropic says the same about its own model. Its skill-creator skill warns that "Claude has a tendency to 'undertrigger' skills -- to not use them when they'd be useful", and ships a tool to rewrite descriptions so they match more requests. The description field, 1,024 characters at most, is what decides whether a skill does anything at all.

Security#

A skill is instructions an agent follows plus, often, scripts it runs with the user's permissions. Anthropic's launch engineering post warned that malicious skills may "direct Claude to exfiltrate data and take unintended actions", and its docs still say to "use Skills only from trusted sources". A year of research shows why.

What security studies of skill registries found

Studies of public skill registries, Jan to Aug 2026; each has its own denominator

Study (what it sells)WhenSampleFinding
Liu et al. (academic)Jan 202631,132 skills from two marketplaces26.1% with at least one vulnerability; 5.2% "strongly suggesting malicious intent"
Koi, via The Hacker News (security)Feb 2026All 2,857 skills on ClawHub341 malicious (11.9%), 335 from one campaign
Antiy CERT (antivirus)Feb 2026ClawHub's history1,184 malicious packages from 12 author IDs
Snyk (scanning; skills.sh audit partner)Feb 20263,984 skills from ClawHub and skills.sh36.82% with a flaw, 13.4% critical, 76 malicious payloads
Liu et al., USENIX Security 2026 (academic)Feb 202698,380 skills from two registries157 confirmed malicious; all removed after disclosure
ClawScan (ClawHub and NVIDIA)Jun 202667,453 skill versions on ClawHub206 malicious, 25,504 suspicious verdicts
Zenity Labs (agent security)Aug 2026One typosquatted family on skills.sh1.7M+ aggregate installs before removal
Don't compare the rates directly: each study sampled different registries and counted different things. ClawHub, OpenClaw's registry, had notoriously loose publishing and accounts for most of the malware; the academic studies are the only ones with no product to sell.

Sources: Liu et al.; Liu et al., USENIX Security; The Hacker News; Antiy; Snyk; OpenClaw; Zenity Labs

The academic baseline is Liu et al., who collected 42,447 skills from two marketplaces in December 2025 and analyzed 31,132. They found that "26.1% of skills contain at least one vulnerability", data exfiltration in 13.3% and privilege escalation in 11.8%, and that skills bundling scripts were 2.12 times likelier to be vulnerable. Most of those are flaws rather than attacks; the paper put 5.2% at "high-severity patterns strongly suggesting malicious intent". The attacks are what grew in 2026.

The first big campaign hit ClawHub, the registry for the OpenClaw agent. In February The Hacker News reported that Koi Security audited all 2,857 skills on it and found 341 malicious, 335 of them from one campaign whose fake "prerequisite" step installed the Atomic macOS Stealer. Antiy CERT later counted 1,184 malicious packages in ClawHub's history, from 12 author IDs. Snyk, which sells scanning and audits skills.sh, sampled 3,984 skills across ClawHub and skills.sh: 1,467 (36.82%) had at least one flaw, 534 (13.4%) a critical one, and 76 carried malicious payloads, 8 of them still live when it published.

The mainstream registry was hit in July. Zenity Labs, which sells agent security, found a family of look-alike skills imitating Paperclip and Browser Use that were "trojanized on July 11" after being listed clean. By 2 August they had more than 1.7 million aggregate installs on skills.sh. Zenity notes that "these counters are not user-unique", and Vercel and GitHub removed the skills within 12 hours of its outreach.

The attack doesn't need a script. Skill-Inject, an academic benchmark of 202 injection-task pairs, found "up to 80% attack success rate with frontier models" from instructions hidden in skill files. The registries' response has mostly been scanning, which helps with known payloads and not with a well-written instruction.

How registries and platforms responded

Security measures for skills, Feb to Oct 2026

  1. 7 Feb 2026

    ClawHub scans every skill with VirusTotal

    Source: OpenClaw

  2. 17 Feb 2026

    skills.sh adds security audits

    Gen, Socket and Snyk audit more than 60,000 skills; flagged skills are hidden.

    Source: Vercel

  3. 19 May 2026

    NVIDIA signs its verified skills

    Scanned, and signed with OpenSSF Model Signing so a download can be checked.

    Source: NVIDIA

  4. 1 Jun 2026

    ClawScan publishes its verdicts

    206 malicious and 25,504 suspicious of 67,453 skill versions.

    Source: OpenClaw

  5. 3 Jun 2026

    Trail of Bits bypasses the scanners

    Recommends curated marketplaces instead.

    Source: Trail of Bits

  6. 6 Aug 2026

    Zenity: 1.7M installs of trojanized skills

    Removed within 12 hours of the report.

    Source: Zenity Labs

  7. 1 Sep 2026

    AIR raises $50M to vet agent add-ons

    It says it filters out about 27% of the skills and add-ons it finds online.

    Source: TechCrunch

  8. 2 Oct 2026

    Anthropic turns on skill scanning for Enterprise

    On by default for Enterprise organizations that hadn't set it; a fail blocks the skill.

    Source: Claude Help Center

Most responses are scanners, and scanners can be beaten. Signing, which proves who published a skill rather than whether it's safe, is still rare, and the spec has no security or signing section.

Anthropic's scanning, per its Help Center, only covers skills added after it's turned on; skills already in an organization aren't scanned.

Skills as distribution#

For developer-tool companies, skills became a way to reach customers through their agents. When we probed in early October, more than 20 vendor domains served a skill index at /.well-known/agent-skills/index.json or the older /.well-known/skills/ path, the convention proposed in a Cloudflare RFC whose current version adds a sha256 digest for every file. An agent can find a company's skills from its domain alone.

Skills served from vendors' own domains

Skills listed in each domain's /.well-known skill index, probed early Oct 2026

Skills served from vendors' own domains
LabelValue
Hugging Face25
Render21
Clerk20
Cloudflare16
Netlify14
Stripe10 (old /skills/ path only)
Paddle10
Vercel9
Neon9
LiveKit7
ElevenLabs7
Resend5
Supabase2
Fly.io2
Hosting, auth, payments and AI-infrastructure companies got there first. Notion, Prisma, Turso, Firecrawl and Browserbase serve one skill each.

Source: host0 probe of https://<domain>/.well-known/{agent-skills,skills}/index.json, early Oct 2026

Documentation hosts made it the default. Mintlify put a skill file at /.well-known/skills/default/skill.md on every docs site it hosts in January. The traffic followed: Mintlify, which sells docs hosting, says agents went from 20.8% of traffic to its docs in February to 66% in August, when it counted 257 million agent requests against 131 million human page loads, and that 83% of agent traffic came through Markdown pages, /llms.txt or agent skills.

Agents' share of traffic to Mintlify-hosted docs

Agent requests as a share of all traffic to docs sites Mintlify hosts, 2026

Agents' share of traffic to Mintlify-hosted docs
LabelValue
Feb 202620.8%
Aug 202666%
In six months agents went from a fifth of docs traffic to two thirds, by Mintlify's count. If an agent is the main reader of your docs, a skill is the version written for it.

Source: Mintlify, State of Knowledge 2026

The other channels are the install command and the marketplace. A GitHub code search in early October found about 41,600 README files containing npx skills add (an estimate; code search counts copies). Anthropic's Claude Marketplace opened on 23 September with "more than 2,000" connectors and plugins built on "MCP and Agent Skills". We found no paid first-party skill store at Anthropic, OpenAI or GitHub: Anthropic told VentureBeat in December that "there are no revenue-sharing arrangements at this time", and skills are included in paid Claude plans at no extra cost.

What this means if you build with AI#

Skills are the cheapest way to teach an agent how you work and how a product is meant to be used. The data points to a few habits.

  1. Read a skill before you install it. It's a Markdown file and maybe a script; read both. A skill runs with your agent's permissions, and the install counter told 1.7 million installers that a trojanized family was popular.
  2. Prefer official and vendor skills. Install from the company that makes the product, its GitHub organization or its own domain's /.well-known/ index, or write your own. Anthropic's own advice is to use skills you created yourself or got from Anthropic.
  3. Don't treat a scan as a clean bill of health. Registry scanners can be beaten in under an hour. A pass means no known payload was found, not that the instructions are safe.
  4. Write descriptions that trigger. The description is the only part the agent sees until it decides to use the skill. Say what it does and when to use it, using the words people will type. Agents undertrigger skills, so test whether yours fires.
  5. Keep a docs index in AGENTS.md for what must always apply. In Vercel's evals an always-loaded 8KB index beat a skill the agent skipped. Use a skill for the occasional procedure and AGENTS.md for the rules of the repo.
  6. Curate, don't generate. Self-written skills gave no benefit on average in SkillsBench. A skill that captures what you actually learned beats one the model wrote from what it already knew.
  7. Keep skills small and few. Focused skills beat big bundles in SkillsBench, and Claude Code drops descriptions once the listing passes 1% of context. Uninstall what you don't use.
  8. Use a skill with MCP, not instead of it. The skill carries the how and the MCP server the live data. In Supabase's eval the pair beat MCP alone every time.
  9. If you build a developer tool, ship it as a skill. Put a SKILL.md in a public repo, serve an index from your domain's /.well-known/agent-skills/, and give people an npx skills add line. Agents are already the main readers of many docs sites.

host0 ships its deploy as a skill: an agent reads host0.ai/skill.md, runs publish.sh on a folder or file, and gets back a URL to share.

Methodology#

This post is built on a data pack we compiled in early October 2026. Five research agents worked in parallel, one per angle: the standard and its adoption timeline, ecosystem size and distribution, security, skills vs MCP, and skills in practice. We then spot-checked about 30 of the numbers the post leans on: we fetched each primary page live and pulled the exact sentence, and re-queried live sources (the GitHub and npm APIs, the skills.sh leaderboard, SkillsMP, the MCP Registry, Wayback snapshots and vendors' /.well-known/ indexes). Each claim carries a tier: verified against the primary source that day, confirmed by two or more independent outlets when the primary was gone, or single-sourced. Before publishing we re-opened every single-sourced page we cite and dropped anything it no longer said.

We left out several claims that circulate widely:

  • "Snyk found 1,467 malicious skills." Snyk's 1,467 is skills with any flaw; 76 were malicious.
  • "1.7 million people installed malware." Zenity says the counters aren't user-unique.
  • An Anthropic skills marketplace with a 15% revenue share in May 2026. We found no Anthropic source; the real launch is the Claude Marketplace in September.
  • Higher recounts of the ClawHub campaign, found only on aggregators.
  • Any single skills.sh counter value as a growth rate, or npm downloads as users.
  • A precise count of SKILL.md files on GitHub. Code-search totals are estimates and include copies.
  • Details we couldn't re-confirm on the source page: the exact totals on skills.sh's official makers page and the date the Claude API took skills out of beta.

Limitations:

  • Conflicts of interest run through almost everything. Vercel runs skills.sh, maintains the CLI, publishes the most-installed skill and counts the installs. Snyk, Socket, Gen, Zenity, Koi (now part of Palo Alto Networks), Antiy, Trail of Bits and AIR sell scanning, vetting or audits. Anthropic created the standard and sells Claude; OpenAI's researchers wrote the Codex paper about their own product; Supabase and Mintlify benefit from skills looking useful. Only Liu et al., SkillsBench, SWE-Skills-Bench and Skill-Inject have no product attached.
  • Installs and downloads aren't people. Both are anonymous CLI telemetry, inflated by bundles and by agents running the CLI themselves.
  • Denominators differ. The security studies sample different registries at different times; ClawHub figures describe one loosely moderated registry, not the ecosystem.
  • Everything moves. Stars, installs and registry counts change by the hour; we give the date we read each one.

Open questions#

The public data leaves gaps:

  1. What happened to the skills.sh counter? It jumped from about 91,000 to 609,966 in May, and Vercel hasn't said why.
  2. How big is the top skill, really? Vercel says even the most-installed skill is "less than 1%" of installs, but 3.7 million find-skills installs is about 1.3% of 280 million.
  3. How many people use skills? No registry publishes unique installers, and Anthropic has published no adoption number for Claude. OpenAI's Codex paper is the only first-party figure with a denominator.
  4. Does a skill alone beat MCP alone? Supabase compared MCP with MCP plus a skill; nobody has a skill-only arm on the same tasks.
  5. How much of skills.sh is flagged? Its three audit partners scan every skill, but there's no public total.
  6. Who will govern the standard? MCP and AGENTS.md went to a foundation; Agent Skills is still run by Anthropic.
  7. Will the spec adopt signing? NVIDIA signs its skills and the discovery RFC adds digests, but the spec has no security section.

We plan to come back to several of these with data of our own.

ResearchAgent skills