The Skills Gold Rush: 600,000 Stars, and the Attack That Came With Them (2026)
Quick verdict
Agent skills have become the distribution format of the agent era: five skills repositories sit on GitHub Trending today with roughly 600,000 stars combined, and Cloudflare has shipped an official one. The same week, PromptArmor demonstrated a malicious skill in Databricks Genie exfiltrating tenant data and phishing credentials through the user's own browser — passing four controls enterprises rely on, none of which was individually broken.
The Number
Open GitHub Trending today and count. Of the thirteen repositories on the page, five are agent skills — and together they carry roughly 600,000 stars:
| Repository | Language | Stars | What it is |
|---|---|---|---|
| mattpocock/skills | Shell | 280,241 | "Skills for Real Engineers. Straight from my .agents directory" |
| addyosmani/agent-skills | JavaScript | 103,081 | Production-grade engineering skills for AI coding agents |
| ayghri/i-have-adhd | Python | 55,461 | A skill to stop your coding agent from burying the answer |
| cathrynlavery/diagram-design | HTML | 45,411 | Editorial diagram design, 42 types, "no Mermaid slop" |
| cloudflare/security-audit-skill | JavaScript | 26,308 | Multi-phase security audits with machine-readable findings |
That is not a niche. That is an app store forming in public, and this week Cloudflare — a security company — started publishing into it.
What a Skill Actually Is
A skill is unglamorous by design: a folder containing a manifest with instructions, plus optional scripts, references, and assets. The agent reads the manifest when the task calls for it, loads what it needs, and moves on. Instruction text is read at use time rather than baked into the model.
That design is why skills won. Prompts are throwaway strings; skills are versioned, reviewable, composable artifacts that live in a repository, get code review, and can be shared. The context cost stays near zero until the skill is actually invoked — an agent can have hundreds of skills available without carrying their weight in every conversation.
The five trending repositories map the ecosystem's maturity stages:
- mattpocock/skills at 280,000 stars is the anchor: a well-known educator publishing his personal working set, which is the most honest advertisement a skill collection can have
- addyosmani/agent-skills covers the production-engineering layer
- i-have-adhd solves a universal annoyance — agents that bury the answer under three paragraphs of preamble — with a single-sentence directive. It is the funniest repository on the list and the most honest about why skills matter: output format is a product decision
- diagram-design encodes a design standard (self-contained HTML+SVG, no shadows, explicit ban on Mermaid's default look) — a skills repository that ships taste rather than code
- cloudflare/security-audit-skill is the signal worth underlining: when an infrastructure company ships an official skill for security audits, the format has crossed from enthusiast practice into enterprise distribution
The Part Nobody Put on Trending
On October 5 — three days before that list — the security firm PromptArmor published a demonstration that matters more than any star count.
Databricks Genie Code, the company's enterprise data agent, executes skills. PromptArmor constructed a malicious one and walked it through a four-step chain. To be precise about what this is: a responsible-disclosure demonstration, not a confirmed breach. But every step of the chain worked.
- The user asks Genie to analyze data with an uploaded skill. Genie loads skills from the user's personal workspace, not from an organization-governed catalog
- Genie executes the skill's code. A guardrail agent screens commands and flags things like "send data to a third party" — it allowed this one through
- Genie prompts the user to open the full analysis result
- On render, the skill's pre-embedded tenant data is read by the page's script, and the user's own browser sends it to an attacker-controlled server — while a convincing phishing login layer is overlaid on the result. No human approval anywhere in the chain
Why Four Controls Failed at Once
The finding's value is in the table. None of these controls was individually broken; together they left the exfiltration path uncovered.
| Control | Why it did not apply |
|---|---|
| Organization-level skill governance | Genie loaded from a personal workspace — the governed catalog does not reach that layer |
| Guardrail agent | Databricks states auto-allow "is not a security boundary" — it prevents untrusted input from running automatically, and is the documented default and recommended mode |
| Code-environment egress rules | The environment genuinely did not permit outbound connections. The exfiltration did not use the environment — it used the browser |
| Chat display sandbox | The display layer fetched nothing from the tenant. The data was embedded by the skill before rendering, so there was nothing for the sandbox to block |
The detail worth carrying away is the identity of the exfiltration channel. The request originated from the employee's own browser — home broadband, café Wi-Fi, or the corporate VPN address — carrying a valid session, a browser fingerprint, and every characteristic of a legitimate user. Trusted-egress configurations do not sit on that path. Domain allowlists do not stop a well-formed HTTPS request. And this pattern of traffic is unremarkable enough that alerting on it produces false positives by the million.
In other words: the same property that makes skills useful — rendering rich, executable output through the user's own client — is the property that defeats the perimeter. And it connects directly to what we documented in the GEO poisoning campaign: the rendered surface is now an attack surface, whether the payload arrives through a poisoned web page or a reviewed-looking skill file.
The Rule This Establishes
Skills are the new apps, which means they inherit the app-store playbook — including its security history. The industry has been here before: package registries with typosquatting, browser extensions with over-broad permissions, Word macros. The mitigation pattern is known:
- Govern the catalog, not the marketplace. Personal workspaces must not be a shadow distribution channel. Route skills through a reviewable, versioned catalog — and confirm the agent actually loads from it
- Review the artifact, not the logic. The malicious behavior was not in the readable code. A skill that asks an agent to render HTML is producing an execution surface; treat DOM output as code
- Treat rendering as egress. If the output can contain markup, the user's browser is part of your network path. Sandbox the renderer, restrict external resource loads, and strip embedded data from generated views
- Do not count the guardrail. Databricks is refreshingly candid that auto-allow is not a security boundary. Wherever your agent has an equivalent — an auto-approved tool, a pre-approved action list — apply the same skepticism
- Assume the marketplace is polluted. PromptArmor notes skill marketplaces are already seeded with malicious entries, and there is no widely deployed signing or provenance standard
Summary
The skills ecosystem is the most encouraging thing on GitHub this week — 600,000 stars of people publishing how they work, with an infrastructure company joining them. It is also a supply chain that has already been demonstrated exploitable, through a chain that used none of the classic attacker moves: no zero-day, no privilege escalation, no firewall breach. Every step stayed inside the product's designed behavior.
That is the pattern of the whole agent era, in one article: the capability and the attack surface are the same artifact. Skills will keep winning because they make agents better. The teams that keep the wins will be the ones that governed them before the incident report, not after.
If you run coding agents with third-party skills today, do one thing this week: list every skill on every machine, and find out whether it came from a catalog or from someone's personal workspace.
Related Articles
Keep reading