較早收集於 4h

Vercel Skills 達 62,000 個並啟安全審核

Vercel Skills 達 62,000 個並啟安全審核
PostLinkedIn
閱讀原文: Vercel News
#agent-skills#cli-install#audits-leaderboardvercel-skills

💡62K open skills for coding agents now security-audited—safely supercharge your AI dev workflow.

⚡ 30-Second TL;DR

有什麼變化

生態系統從 React 文件成長至 62,000 個 skills 與 200 萬 npx skills CLI 安裝

為什麼重要

提升開發者對社群 skills 用於 AI 代理的信心,降低快速成長中的安全風險。讓代理能力迭代更快,使用經審核的知識來源。定位 Vercel 為代理程式碼工作流程的關鍵基礎設施。

下一步行動

Run `npx skills` to install top skills into your Cursor or Claude coding agent.

誰應關注:Developers & AI Engineers

關鍵要點

  • 生態系統從 React 文件成長至 62,000 個 skills 與 200 萬 npx skills CLI 安裝
  • CLI 可一鍵安裝至 Cursor、Claude Code 等 10+ 程式碼代理
  • 與 Socket、Snyk 等安全夥伴合作審核所有 skills,防範遠端殼等威脅
  • 新 Audits 排行榜提供每個 skill 的安全評估

🧠 深度解析

背景與延伸:來自公開資料,非原文內容。引用 8 個來源。

🔑 增強重點摘要

  • Vercel Skills ecosystem reached 62,000 skills and 2 million npx CLI installs, with top skills from Vercel achieving a combined 66,000 installs[5].
  • Skills.sh serves as an open directory for reusable AI agent skills, installable via CLI into agents like Cursor and Claude, with rapid adoption post-launch reaching tens of thousands of installs[8][6].
  • Security enhancements include partnerships with Socket and Snyk for audits, plus a new integration with Gen's Agent Trust Hub (announced Feb 17, 2026) providing four-tier risk ratings (Safe, Low Risk, High Risk, Critical Risk) directly in skills.sh for over 6 million developers[3][4].
  • New Audits leaderboard displays per-skill security assessments to promote transparency and safety[article].
  • Vercel evals show static AGENTS.md (8KB compressed docs) outperforming skills (100% vs 79% pass rate on Next.js tasks), highlighting complementary uses: static for broad knowledge, skills for specific actions[1][7].
📊 競品分析▸ Show
FeatureVercel Skills.shGen Agent Trust Hub
Core FunctionOpen directory for AI agent skills with CLI installsIndependent AI-driven security verification and risk ratings
SecurityAudits by Socket, Snyk; Audits leaderboard; Gen integration (Safe to Critical Risk)Four-tier ratings embedded in skills.sh
Adoption62K skills, 2M installs, 6M developersIntegrated into Vercel platform
PricingFree/open ecosystemNot specified

🛠️ 技術深入

  • Skills are modular capabilities published to skills.sh, installed via npx CLI (e.g., one-command into 10+ agents like Cursor, Claude), enabling on-demand actions such as commerce (Universal Commerce Protocol) and workflows (durable async functions with retry logic)[6][article].
  • Security audits target threats like remote shells; Gen's ATH uses AI for independent verification classifying skills as Safe (best practices), Low Risk (minor indicators), High Risk (significant concerns), or Critical Risk (severe/malicious)[3][4].
  • Eval data: Skills with default behavior matched baseline 53% pass rate (agent invocation failure in 56% cases); explicit instructions boosted to 79%, but static 8KB AGENTS.md achieved 100% on Next.js 16 API tasks (perfect Build/Lint/Test scores)[1][7].
  • Failure patterns: Agent non-invocation, fragile triggers sensitive to phrasing; skills suit vertical workflows, AGENTS.md for horizontal Next.js knowledge[1].

🔮 前景展望AI analysis grounded in cited sources

Vercel's Skills ecosystem, bolstered by security partnerships like Gen, Socket, and Snyk, establishes a trust layer for AI agents amid rapid growth, potentially standardizing reusable actions across 6M developers while evals suggest hybrid static+skills approaches for optimal performance, reducing execution failures in agentic workflows.

時間線

2026-02
Vercel launches Skills.sh open ecosystem for AI agent skills with rapid adoption to tens of thousands of installs
2026-02-17
Gen and Vercel partner to integrate Agent Trust Hub for independent safety ratings on skills.sh
📰

AI 週報

閱讀本週精選 AI 大事摘要 →

👉相關動態

AI 策展新聞聚合。所有內容版權歸原始發布者所有。
原始來源: Vercel News

這是摘要,不是原文。去看原站,或訂閱每週簡報。

每週 AI 簡報

每週一封,可隨時退訂。