The State of AI Skill Security

Agents are running skills pulled from public registries with almost no behavioral scrutiny. We grade them — prompt-injection resistance, data-leak resistance, refusal/usability, and manifest hygiene — against OWASP, MITRE ATLAS and the EU AI Act. This report is what those measurements add up to across the ecosystem.

  • The failure modes that show up most often, and how often.
  • How grades cluster by source and skill type.
  • What "measured, not proven" means for your own risk review.

Honest framing throughout — every number is a measurement over a finite number of trials, not a safety guarantee.

Get the State of AI Skill Security report

What we're measuring across the skills people actually run — the common failure modes, by the numbers. One email when it's out. No spam, unsubscribe anytime.

Prefer to just try it? Grade a skill free →