The State of AI Skill Security
Agents are running skills pulled from public registries with almost no behavioral scrutiny. We grade them — prompt-injection resistance, data-leak resistance, refusal/usability, and manifest hygiene — against OWASP, MITRE ATLAS and the EU AI Act. This report is what those measurements add up to across the ecosystem.
- The failure modes that show up most often, and how often.
- How grades cluster by source and skill type.
- What "measured, not proven" means for your own risk review.
Honest framing throughout — every number is a measurement over a finite number of trials, not a safety guarantee.
Get the State of AI Skill Security report
What we're measuring across the skills people actually run — the common failure modes, by the numbers. One email when it's out. No spam, unsubscribe anytime.
Prefer to just try it? Grade a skill free →