Stalecollected in 4h

Vercel Skills hits 62K with security audits

Vercel Skills hits 62K with security audits
PostLinkedIn
Read original on Vercel News

💡62K open skills for coding agents now security-audited—safely supercharge your AI dev workflow.

⚡ 30-Second TL;DR

What Changed

Ecosystem grew from React docs to 62,000 skills and 2M npx skills CLI installs

Why It Matters

Boosts developer confidence in using community skills for AI agents, reducing security risks amid rapid growth. Enables faster iteration on agent capabilities with vetted knowledge sources. Positions Vercel as key infrastructure for agentic coding workflows.

What To Do Next

Run `npx skills` to install top skills into your Cursor or Claude coding agent.

Who should care:Developers & AI Engineers

🧠 Deep Insight

Web-grounded analysis with 8 cited sources.

🔑 Enhanced Key Takeaways

  • Vercel Skills ecosystem reached 62,000 skills and 2 million npx CLI installs, with top skills from Vercel achieving a combined 66,000 installs[5].
  • Skills.sh serves as an open directory for reusable AI agent skills, installable via CLI into agents like Cursor and Claude, with rapid adoption post-launch reaching tens of thousands of installs[8][6].
  • Security enhancements include partnerships with Socket and Snyk for audits, plus a new integration with Gen's Agent Trust Hub (announced Feb 17, 2026) providing four-tier risk ratings (Safe, Low Risk, High Risk, Critical Risk) directly in skills.sh for over 6 million developers[3][4].
  • New Audits leaderboard displays per-skill security assessments to promote transparency and safety[article].
  • Vercel evals show static AGENTS.md (8KB compressed docs) outperforming skills (100% vs 79% pass rate on Next.js tasks), highlighting complementary uses: static for broad knowledge, skills for specific actions[1][7].
📊 Competitor Analysis▸ Show
FeatureVercel Skills.shGen Agent Trust Hub
Core FunctionOpen directory for AI agent skills with CLI installsIndependent AI-driven security verification and risk ratings
SecurityAudits by Socket, Snyk; Audits leaderboard; Gen integration (Safe to Critical Risk)Four-tier ratings embedded in skills.sh
Adoption62K skills, 2M installs, 6M developersIntegrated into Vercel platform
PricingFree/open ecosystemNot specified

🛠️ Technical Deep Dive

  • Skills are modular capabilities published to skills.sh, installed via npx CLI (e.g., one-command into 10+ agents like Cursor, Claude), enabling on-demand actions such as commerce (Universal Commerce Protocol) and workflows (durable async functions with retry logic)[6][article].
  • Security audits target threats like remote shells; Gen's ATH uses AI for independent verification classifying skills as Safe (best practices), Low Risk (minor indicators), High Risk (significant concerns), or Critical Risk (severe/malicious)[3][4].
  • Eval data: Skills with default behavior matched baseline 53% pass rate (agent invocation failure in 56% cases); explicit instructions boosted to 79%, but static 8KB AGENTS.md achieved 100% on Next.js 16 API tasks (perfect Build/Lint/Test scores)[1][7].
  • Failure patterns: Agent non-invocation, fragile triggers sensitive to phrasing; skills suit vertical workflows, AGENTS.md for horizontal Next.js knowledge[1].

🔮 Future ImplicationsAI analysis grounded in cited sources

Vercel's Skills ecosystem, bolstered by security partnerships like Gen, Socket, and Snyk, establishes a trust layer for AI agents amid rapid growth, potentially standardizing reusable actions across 6M developers while evals suggest hybrid static+skills approaches for optimal performance, reducing execution failures in agentic workflows.

Timeline

2026-02
Vercel launches Skills.sh open ecosystem for AI agent skills with rapid adoption to tens of thousands of installs
2026-02-17
Gen and Vercel partner to integrate Agent Trust Hub for independent safety ratings on skills.sh
📰

Weekly AI Recap

Read this week's curated digest of top AI events →

👉Related Updates

AI-curated news aggregator. All content rights belong to original publishers.
Original source: Vercel News