Skip to main content
AgentSecv0.3.0
Live · refreshed hourly315 skills monitored·last scan May 12, 2026, 07:38 PM UTC

Skill Watch.
Audits in the wild.

Live AgentSec audits of agent skills across the public ecosystem — scored against OWASP AST-10, ranked by trend, and ready to inspect. Pulled from the skill-watchonFrames.

Snapshot

The state of
the skill shelf.

Each row in the dataset is a real skill scanned by AgentSec. These stats roll up the current cohort — the share of skills carrying open findings, the average security score, and where the risk concentrates.

Skills monitored
315
With findings
39
12% of inventory
Clean skills
276
no vulnerabilities flagged
Avg. overall score
70
out of 100
Avg. security score
79
out of 100
Total installs
9,488,900
across monitored skills
Findings by severity

917 total

Critical68
High264
Medium451
Low134
Grade distribution

Mostly C · 278

37 failing (D or F) · 12% of cohort
0
A
0
B
278
C
13
D
24
F
Top categories

Where skills
fail the most.

Each skill's most severe finding gets bucketed into an OWASP AST-10 category. Click a row to drill into the matching skills below.

The inventory

Every skill,
every score.

Filter by grade, isolate skills carrying findings, or search by owner. Each card links straight to the upstream repository on GitHub.

315/315 skills
Sort
#1
ai-video-generation
inference-skills/skills
C
Generate AI videos with Google Veo, Seedance 2.0, HappyHorse, Wan, Grok and 40+ models via inference.sh CLI. Models: Veo 3.1, Veo 3, Seedance 2.0, HappyHorse 1.0, Wan 2.5, Grok Imagine Video, OmniHuman, Fabric, HunyuanVideo. Capabilities: text-to-video, image-to-video, reference-to-video, video editing, lipsync, avatar animation, video upscaling, foley sound. Use for: social media videos, marketing content, explainer videos, product demos, AI avatars. Triggers: video generation, ai video, text to video, image to video, veo, animate image, video from image, ai animation, video generator, generate video, t2v, i2v, ai video maker, create video with ai, runway alternative, pika alternative, sora alternative, kling alternative, seedance, happyhorse
overall74
security88
quality65
maintenance50
1med
145,300 installs
top: AST05·STOR-GIT-MISSING
readmelicensetests
scanned 5 days agogithub →
#2
find-skills
vercel-labs/skills
C
Helps users discover and install agent skills when they ask questions like "how do I do X", "find a skill for X", "is there a skill that can...", or express interest in extending capabilities. This skill should be used when the user is looking for functionality that might exist as an installable skill.
overall74
security88
quality65
maintenance50
1med
1,400,000 installs
top: AST05·STOR-GIT-MISSING
readmelicensetests
scanned 5 days agogithub →
#4
just-scrape
scrapegraphai/just-scrape
C
Search, scrape, crawl, extract structured data, and monitor web pages via the ScrapeGraph AI CLI. Use when the user asks to search the web, scrape a webpage, grab content from a URL, extract JSON from a site, crawl documentation or site sections, monitor a page for changes, inspect request history, check ScrapeGraph credits, or validate API setup.
overall74
security88
quality65
maintenance50
1med
7,100 installs
top: AST05·STOR-GIT-MISSING
readmelicensetests
scanned 5 days agogithub →
#5
soultrace
soultrace-ai/soultrace-skill
C
Take a personality assessment via the SoulTrace API. Use when the user wants to take a personality test, discover their psychological archetype, understand their personality traits, or get a color-based personality profile. The API uses a 5-color psychological model (White=structure, Blue=understanding, Black=agency, Red=intensity, Green=connection) with Bayesian adaptive question selection to classify users into one of 25 archetypes. Triggers on: personality test, personality assessment, what's my personality, take a quiz, archetype test, color personality, soultrace.
overall74
security88
quality65
maintenance50
1med
6,800 installs
top: AST05·STOR-GIT-MISSING
readmelicensetests
scanned 5 days agogithub →
#6
grill-me
mattpocock/skills
C
Interview the user relentlessly about a plan or design until reaching shared understanding, resolving each branch of the decision tree. Use when user wants to stress-test a plan, get grilled on their design, or mentions "grill me".
overall74
security88
quality65
maintenance50
1med
94,800 installs
top: AST05·STOR-GIT-MISSING
readmelicensetests
scanned 5 days agogithub →
#7
microsoft-foundry
microsoft/azure-skills
C
Deploy, evaluate, and manage Foundry agents end-to-end: Docker build, ACR push, hosted/prompt agent create, container start, batch eval, continuous eval, prompt optimizer workflows, agent.yaml, dataset curation from traces. USE FOR: deploy agent to Foundry, hosted agent, create agent, invoke agent, evaluate agent, run batch eval, continuous eval, continuous monitoring, continuous eval status, optimize prompt, improve prompt, prompt optimizer, optimize agent instructions, improve agent instructions, optimize system prompt, deploy model, Foundry project, RBAC, role assignment, permissions, quota, capacity, region, troubleshoot agent, deployment failure, create dataset from traces, dataset versioning, eval trending, create AI Services, Cognitive Services, create Foundry resource, provision resource, knowledge index, agent monitoring, customize deployment, onboard, availability. DO NOT USE FOR: Azure Functions, App Service, general Azure deploy (use azure-deploy), general Azure prep (use azure-prepare).
overall74
security88
quality65
maintenance50
1med
311,500 installs
top: AST05·STOR-GIT-MISSING
readmelicensetests
scanned 5 days agogithub →
#8
grill-with-docs
mattpocock/skills
C
Grilling session that challenges your plan against the existing domain model, sharpens terminology, and updates documentation (CONTEXT.md, ADRs) inline as decisions crystallise. Use when user wants to stress-test a plan against their project's language and documented decisions.
overall74
security88
quality65
maintenance50
1med
5,000 installs
top: AST05·STOR-GIT-MISSING
readmelicensetests
scanned 4 days agogithub →
#8
improve-codebase-architecture
mattpocock/skills
C
Find deepening opportunities in a codebase, informed by the domain language in CONTEXT.md and the decisions in docs/adr/. Use when the user wants to improve architecture, find refactoring opportunities, consolidate tightly-coupled modules, or make a codebase more testable and AI-navigable.
overall74
security88
quality65
maintenance50
1med
5,800 installs
top: AST05·STOR-GIT-MISSING
readmelicensetests
scanned 5 days agogithub →
#9
diagnose
mattpocock/skills
C
Disciplined diagnosis loop for hard bugs and performance regressions. Reproduce → minimise → hypothesise → instrument → fix → regression-test. Use when user says "diagnose this" / "debug this", reports a bug, says something is broken/throwing/failing, or describes a performance regression.
overall74
security88
quality65
maintenance50
1med
4,900 installs
top: AST05·STOR-GIT-MISSING
readmelicensetests
scanned 4 days agogithub →
#9
to-prd
mattpocock/skills
C
Turn the current conversation context into a PRD and publish it to the project issue tracker. Use when user wants to create a PRD from the current context.
overall74
security88
quality65
maintenance50
1med
4,700 installs
top: AST05·STOR-GIT-MISSING
readmelicensetests
scanned 4 days agogithub →
#9
sleek-design-mobile-apps
sleekdotdesign/agent-skills
C
Use when the user wants to design a mobile app, create screens, build UI, or interact with their Sleek projects. Covers high-level requests ("design an app that does X") and specific ones ("list my projects", "create a new project", "screenshot that screen").
overall74
security88
quality65
maintenance50
1med
92,100 installs
top: AST05·STOR-GIT-MISSING
readmelicensetests
scanned 5 days agogithub →
#10
tdd
mattpocock/skills
C
Test-driven development with red-green-refactor loop. Use when user wants to build features or fix bugs using TDD, mentions "red-green-refactor", wants integration tests, or asks for test-first development.
overall74
security88
quality65
maintenance50
1med
4,800 installs
top: AST05·STOR-GIT-MISSING
readmelicensetests
scanned 4 days agogithub →
#10
to-issues
mattpocock/skills
C
Break a plan, spec, or PRD into independently-grabbable issues on the project issue tracker using tracer-bullet vertical slices. Use when user wants to convert a plan into issues, create implementation tickets, or break down work into issues.
overall74
security88
quality65
maintenance50
1med
4,900 installs
top: AST05·STOR-GIT-MISSING
readmelicensetests
scanned 4 days agogithub →
#10
write-a-skill
mattpocock/skills
C
Create new agent skills with proper structure, progressive disclosure, and bundled resources. Use when user wants to create, write, or build a new skill.
overall74
security88
quality65
maintenance50
1med
4,600 installs
top: AST05·STOR-GIT-MISSING
readmelicensetests
scanned 5 days agogithub →
#10
tzst
xixu-me/skills
C
Use when the user needs to create, extract, flatten, list, test, install, script, or troubleshoot `tzst` CLI workflows for `.tzst` or `.tar.zst` archives, including compression levels, streaming mode, extraction filters, conflict resolution, JSON output, or standalone binary setup, even if they describe the archive task without naming `tzst`.
overall74
security88
quality65
maintenance50
1med
4,400 installs
top: AST05·STOR-GIT-MISSING
readmelicensetests
scanned 2 days agogithub →
#12
happyhorse-1-0
agentspace-so/runcomfy-agent-skills
C
runcomfy.com · Text-to-video · GitHub
overall74
security88
quality65
maintenance50
1med
4,600 installs
top: AST05·STOR-GIT-MISSING
readmelicensetests
scanned 5 days agogithub →
#14
remotion-render
inference-sh-skills/skills
C
Render videos from React/Remotion component code via inference.sh. Pass TSX code, get MP4. Supports all Remotion APIs: useCurrentFrame, useVideoConfig, spring, interpolate, AbsoluteFill, Sequence. Configurable resolution, FPS, duration, codec. Use for: programmatic video generation, animated graphics, motion design, data-driven videos, React animations to video. Triggers: remotion, render video from code, tsx to video, react video, programmatic video, remotion render, code to video, animated video, motion graphics code, react animation video
overall74
security88
quality65
maintenance50
1med
4,300 installs
top: AST05·STOR-GIT-MISSING
readmelicensetests
scanned 2 days agogithub →
#14
twitter-automation
inference-sh-skills/skills
C
Automate Twitter/X with posting, engagement, and user management via inference.sh CLI. Apps: x/post-tweet, x/post-create (with media), x/post-like, x/post-retweet, x/dm-send, x/user-follow. Capabilities: post tweets, schedule content, like posts, retweet, send DMs, follow users, get profiles. Use for: social media automation, content scheduling, engagement bots, audience growth, X API. Triggers: twitter api, x api, tweet automation, post to twitter, twitter bot, social media automation, x automation, tweet scheduler, twitter integration, post tweet, twitter post, x post, send tweet
overall74
security88
quality65
maintenance50
1med
4,200 installs
top: AST05·STOR-GIT-MISSING
readmelicensetests
scanned 1 day agogithub →
#14
caveman
mattpocock/skills
C
Respond terse like smart caveman. All technical substance stay. Only fluff die.
overall74
security88
quality65
maintenance50
1med
4,600 installs
top: AST05·STOR-GIT-MISSING
readmelicensetests
scanned 5 days agogithub →
#15
flux-2-klein
agentspace-so/runcomfy-agent-skills
C
runcomfy.com · 9B model · 4B model · [GitHub](https://github.com/agentspace-so/runcomfy-skills/tree/main/flux-2-klein
overall74
security88
quality65
maintenance50
1med
4,500 installs
top: AST05·STOR-GIT-MISSING
readmelicensetests
scanned 5 days agogithub →
#15
seedance-v2
agentspace-so/runcomfy-agent-skills
C
runcomfy.com · Seedance 2.0 Pro · GitHub
overall74
security88
quality65
maintenance50
1med
4,500 installs
top: AST05·STOR-GIT-MISSING
readmelicensetests
scanned 5 days agogithub →
#15 hot #8
lark-im
larksuite/cli
C
飞书即时通讯:收发消息和管理群聊。发送和回复消息、搜索聊天记录、管理群聊成员、上传下载图片和文件(支持大文件分片下载)、管理表情回复。当用户需要发消息、查看或搜索聊天记录、下载聊天中的文件、查看群成员、管理标记数据时使用。
overall74
security88
quality65
maintenance50
1med
4,300 installs
top: AST05·STOR-GIT-MISSING
readmelicensetests
scanned 1 day agogithub →
#15
zoom-out
mattpocock/skills
C
Tell the agent to zoom out and give broader context or a higher-level perspective. Use when you're unfamiliar with a section of code or need to understand how it fits into the bigger picture.
overall74
security88
quality65
maintenance50
1med
4,700 installs
top: AST05·STOR-GIT-MISSING
readmelicensetests
scanned 4 days agogithub →
#16
triage
mattpocock/skills
C
Triage issues through a state machine driven by triage roles. Use when user wants to create an issue, triage issues, review incoming bugs or feature requests, prepare issues for an AFK agent, or manage issue workflow.
overall74
security88
quality65
maintenance50
1med
4,500 installs
top: AST05·STOR-GIT-MISSING
readmelicensetests
scanned 5 days agogithub →
Showing 24 of 315
Run it yourself

See your skill on the watch list.

Skill Watch is built from agentsec audits run against the public ecosystem. Run the same command on your repo and you'll get the same report — locally, in CI, or before you publish.