{
  "schema_version": "1.1",
  "id": "s9:https://github.com/tech-leads-club/agent-skills",
  "slug": "agent-skills-1rcu2i7",
  "url": "https://feed7.dev/p/agent-skills-1rcu2i7",
  "title": "tech-leads-club/agent-skills",
  "why_included": "A cross-agent skill registry adds scanning, integrity checks, and auditable installs for teams that want reusable coding-agent workflows without blindly trusting marketplace packages.",
  "summary": "Agent Skills packages workflows for Cursor, Claude Code, Copilot, and other agents behind a CLI and MCP server. The repository says marketplace research found **13.4%** of skills had critical issues; its catalog is **100% open source**, contains no binaries, and is scanned before publishing.",
  "practical_implication": "Treat agent skills as executable supply-chain inputs. Pin them through lockfiles and **content hashing**, prefer project-local copies when appropriate, inspect prompts and references, and use the audit log when updating or removing installed capabilities.",
  "agent_context": "Agent Skills packages workflows for Cursor, Claude Code, Copilot, and other agents behind a CLI and MCP server. The repository says marketplace research found **13.4%** of skills had critical issues; its catalog is **100% open source**, contains no binaries, and is scanned before publishing.\n\nTreat agent skills as executable supply-chain inputs. Pin them through lockfiles and **content hashing**, prefer project-local copies when appropriate, inspect prompts and references, and use the audit log when updating or removing installed capabilities.\n\nThe security posture is described by the maintainers, and the marketplace comparison is not substantiated in the supplied material. Human curation and **Snyk Agent Scan** reduce known risks but do not prove that a skill's instructions are safe or suitable for your repository.",
  "source": {
    "name": "GitHub",
    "url": "https://github.com/tech-leads-club/agent-skills",
    "published_at": null
  },
  "source_class": "tool",
  "content_type": "GitHub Repo",
  "layer": "agent",
  "domains": [
    "coding",
    "security"
  ],
  "topics": [
    "skills",
    "harness-engineering",
    "agent-reliability"
  ],
  "verification": {
    "status": "needs_review",
    "label": "Needs Review",
    "method": "unverified",
    "verified_at": null
  },
  "uncertainty": [
    "The security posture is described by the maintainers, and the marketplace comparison is not substantiated in the supplied material. Human curation and **Snyk Agent Scan** reduce known risks but do not prove that a skill's instructions are safe or suitable for your repository."
  ],
  "connected_context": {
    "meaning": "This makes skill governance operational at installation and update time: provenance, pinned content, hashes, inspection, and audit history become part of the agent harness. It reinforces prior warnings that reusable skills are supply-chain dependencies, while narrowing the repository’s own safety claims: scanning and curation reduce exposure but cannot establish behavioral suitability for a specific codebase.",
    "corpus_size": 758,
    "generated_at": "2026-09-13T18:03:55.430Z",
    "connections": [
      {
        "title": "We Vetted 2000 AI Skills Before They Reached Developers — Lucas Palma, Nubank",
        "source_name": "AI Engineer",
        "source_url": "https://www.youtube.com/watch?v=iKQ78wyJEXU",
        "feed7_url": "https://feed7.dev/p/we-vetted-2000-ai-skills-before-they-reached-developers-lucas-palma-nuba-0k4ehkz",
        "reason": "Nubank independently reinforces pre-distribution scanning and governance; this repository adds reproducible installation controls such as lockfiles, content hashes, and update logs."
      },
      {
        "title": "affaan-m/ECC",
        "source_name": "GitHub",
        "source_url": "https://github.com/affaan-m/ECC",
        "feed7_url": "https://feed7.dev/p/ecc-0438yju",
        "reason": "ECC’s broad cross-harness catalog creates exactly the selective-installation and upgrade-audit problem that pinned, inspectable skill dependencies are meant to control."
      },
      {
        "title": "zhaoxuya520/reverse-skill",
        "source_name": "GitHub",
        "source_url": "https://github.com/zhaoxuya520/reverse-skill",
        "feed7_url": "https://feed7.dev/p/reverse-skill-1e4jlfw",
        "reason": "The security router shows why capability-specific skill packs need independent review: structured authorization instructions help workflow consistency but are not a security boundary or proof of safe content."
      }
    ]
  },
  "lifecycle": "Current",
  "published_at": null,
  "modified_at": null,
  "supersedes": [],
  "expires_at": null,
  "formats": {
    "html": "https://feed7.dev/p/agent-skills-1rcu2i7",
    "json": "https://feed7.dev/p/agent-skills-1rcu2i7.json",
    "markdown": "https://feed7.dev/p/agent-skills-1rcu2i7.md"
  }
}