← Founder Notes
Archive

Agent skills are the new supply chain attack vector, and almost none of them are vetted. skillsmp…

Yethikrishna ROriginal on Threads

agent skills are the new supply chain attack vector, and almost none of them are vetted. skillsmp already indexes 1.9 million public skills that run inside the agent's privileged context, with file, shell and env access, and no signing requirement gates any of it.

the biggest app store in software has no review process.

Context

The arXiv study Agent Skills in the Wild (2601.10338), by authors from Quantstamp, Tianjin University and Southern Cross University, analysed 31,132 skills collected from 42,447 across two marketplaces with its SkillScan static and LLM tooling. It found 26.1 percent with at least one vulnerability, 5.2 percent with high-severity patterns suggesting malicious intent, and skills bundling scripts 2.12 times more likely to be vulnerable. Agentman's ecosystem report of 24 June 2026 says SkillsMP had about 1.9 million public skills scraped from GitHub and lists its security review as none, with figures moving week to week. SkillsMP's homepage now says 2,000,000+ open-source Agent Skills.

How it compares

The study did not examine SkillsMP's whole catalog, and its 26.1 percent is a tool-detected rate on the 31,132 it analysed and not confirmed exploits and not a rate across 1.9 million. The 1.9 million is a snapshot, now stated as 2,000,000+ by SkillsMP, so the exact count on 20 September is not established. No signing requirement and no review process were not in a first-party SkillsMP statement; only Agentman's table supports no security review, and it is secondary. The privileges the note lists are the author's description. The paper itself says skills run with implicit trust. That skills are the new supply chain vector is the author's thesis.

Related work

Watch next

  • SkillsMP policy changes and measurements of confirmed malicious skills.

Sources

  1. Agent Skills in the Wild (arXiv 2601.10338)arxiv.org
  2. Agent skills ecosystem report 2026 (Agentman)agentman.ai
  3. SkillsMPskillsmp.com

Provenance

The note above is reproduced unedited from the original post, first published on Threads on 20 September 2026 at 06:19 IST. Sources are the papers and datasets the note draws on.

View the original post
Embed this note
<iframe src="https://founder.myndlabs.tech/notes/embed/agent-skills-are-the-new-supply-chain-attack-DdfVeFtgtXg" width="480" height="420" style="border:0;max-width:100%" loading="lazy" title="Agent skills are the new supply chain attack vector, and almost none of them are vetted. skillsmp…"></iframe>

More notes