A recent study, the Agent Skill Security Census, reveals that a significant majority of AI agent skills lack security audits, despite these audits being concentrated on the most installed applications. Of the nearly 80,000 listed skills, only 12.2% have undergone any audit, yet these audited skills account for over 83% of all installations. Furthermore, more than half of the audited skills carry risk flags, with major vendors like ByteDance Lark, Microsoft, Vercel, Anthropic, Google, and OpenAI appearing on the flagged list. AI
IMPACT Highlights critical security gaps in the AI agent ecosystem, potentially impacting user trust and adoption of AI tools.
RANK_REASON The item reports on a study analyzing the security of AI agent skills, including findings on audits and vulnerabilities. [lever_c_demoted from research: ic=1 ai=1.0]
Read on dev.to — Claude Code tag →
- Agent Skill Security Census
- Anthropic
- Black Hat USA 2026
- ByteDance Lark
- Claude Code
- Gemini CLI
- Microsoft
- Novee Security
- OpenAI
- Skillselion
- Vercel
AI-generated summary · Google Gemini · from 1 sources. How we write summaries →