No red flags found in any of the 11 categories — no credential harvesting, no data exfiltration, no curl-pipe-shell installer. Scanned against the SlowMist agent-security taxonomy, refreshed every 8 hours. Full audit →
by vercel-labs · Agent Tool · ★ 32.0k
Last updated: · Indexed by AgentSkillsHub · Auto-synced every 8h
🔒 Is skills safe to install? View the security audit →
skills The CLI for the open agent skills ecosystem. Supports OpenCode, Claude Code, Codex, Cursor, and 37 more. Install a Skill Source Formats Options Target specific agents (e.g., , ). See Available Agents
| Stars | 31,970 |
| Forks | 2,726 |
| Language | TypeScript |
| Category | Agent Tool |
| License | MIT |
| Quality Score | 71.2087153051932/100 |
| Open Issues | 1195 |
| Last Updated | 2026-09-18 |
| Created | 2026-01-14 |
| Platforms | node |
| Est. Tokens | ~18k |
Looking for a skills alternative? If you're comparing skills with other agent tool tools, these 4 projects are the closest alternatives on Agent Skills Hub — ranked by topic overlap, star count, and community traction.
A hand-picked collection of the finest of resources for the most awesome of agents, Claude Code, the undispute
A 100% free modern JS SaaS boilerplate (React, NodeJS, Prisma). Full-featured: Auth (email, google, github, sl
Use this skill to enable Claude Code to communicate directly with your Google NotebookLM notebooks. Query your
The secure, validated skill registry for professional AI coding agents. Extend Antigravity, Claude Code, Curso
Explore other popular agent tool tools:
skills is The open agent skills tool - npx skills. It is categorized as a Agent Tool with 32.0k GitHub stars.
skills is primarily written in TypeScript.
You can find installation instructions and usage details in the skills GitHub repository at github.com/vercel-labs/skills. The project has 32.0k stars and 2726 forks, indicating an active community.
skills is released under the MIT license, making it free to use and modify according to the license terms.
The top alternatives to skills on Agent Skills Hub include awesome-claude-code, open-saas, notebooklm-skill. Each offers a different approach to the same problem space — compare them side-by-side by stars, quality score, and community activity.
Grades come from a rule-based scan built on the SlowMist agent-security taxonomy, covering 11 red-flag categories including credential harvesting, data exfiltration, and curl | sh installers. It is a first-layer scan, not a manual audit — we say so rather than overstate it.
The scale of the problem is documented independently: Liu et al. (2026), in a study of 31,132 agent skills, report that 26.1% contain security vulnerabilities. Our own full-catalog census is published as a citable open dataset.
Sources & who's responsible: