670,000 agent skills, no trust layer: bot scan finds 69% never reliably fire

markjeffrey · x · 2026-09-22

DavFields pointed a bot at 14 sources (HN, GitHub, Reddit, X, YouTube) collecting 2,719 posts in 48 hours about agent skills: 960 were feature requests, 526 complaints about broken installs. Key findings: a static scan of 216 public Claude Code skills found 69% don't reliably trigger; security scanners contradict each other on the same skill (Gen: Safe, Socket: 0 alerts, Snyk: Critical Risk), and Snyk's own audit flags 36.8% of 3,984 skills with at least one issue. Conclusion: contradictory trust signals are worse than none across 670,000 skills with no trust layer.

Original post →

More from coding & agent

coding & agent channel →