agentsclimarketplace

Skill scout

Skill caoergou/erics-skills/skills/skill-scout

Eric's collection of AI agent skills.

Install
npx -y skills add caoergou/erics-skills --skill skill-scout

Assembled from the repository path, not quoted from the project. Check it against their README if it does not work.

One thing to look at

  • 0 stars0 stars. Stars are a popularity signal and not a quality one, but at this level it is likely that nobody has read this closely except its author, and you would be relying on your own review.

What its author says it does

Copied from the file, not written here

Periodic ecosystem radar for AI agent skills. Scans skills.sh, ClawHub, Loaditout, AgentSkillsHub, LobeHub, OpenForge, GitHub and more — produces a shareable digest with security assessments for team evaluation and ecosystem awareness.

SKILL.md

8.0 KB, ~2.0k tokens by cl100k_base, as published. Nobody here has run it

Skill Scout

A periodic ecosystem radar for AI agent skills. Produces a shareable, newsletter-style digest that answers two questions:

  1. What's worth adopting? — Trending skills across all major registries, with security vetting, for team evaluation and selection.
  2. Where is the ecosystem going? — Platform growth, new categories, security landscape, emerging patterns.

The output is designed to be directly shareable — paste into Slack, Lark, a team wiki, or a blog post.

Scope: This skill is for discovery and curation, not for searching by specific requirements. For that, use find-skills.


Workflow

Step 1: Gather — Multi-Registry Scan

Fetch from all major sources in parallel. Each registry surfaces different signals:

SourceWhat to FetchKey Signal
skills.sh/trending pageInstall counts, hot/trending boards (91K+ skills)
ClawHubHomepage + popularStaff picks, download counts (3.2K+ skills)
AgentSkillsHubLeaderboardA-F security grades, heat score (13.8K+ skills)
LoaditoutBrowse pageSecurity grades, MCP + SKILL.md unified (21K+ entries)
LobeHubSkills marketplaceCommunity ratings (100K+ skills)
OpenForgeMarketplaceMulti-framework coverage, DeFi/non-coding categories
GitHubTrending repos with SKILL.mdStars, forks, publisher reputation
WebBlog posts, curated lists, announcementsQualitative signal, community buzz

How:

  • Registry pages: WebFetch each URL
  • Web signal: mcp__exa__web_search_exa — e.g. "AI agent skills trending new noteworthy {current_year}"
  • GitHub: mcp__exa__web_search_exa — e.g. "SKILL.md agent skill site:github.com"

Also monitor well-known publishers for new releases:

PublisherRepoKnown For
anthropicsskillsOfficial reference (82K+ stars)
vercel-labsagent-skillsOfficial Vercel collection (21K+ stars)
antfuskillsCommunity-curated
nicepkgtool-belt, vibe-createUtility & frontend
larksuitelark-skillsLark/Feishu integrations
tech-leads-clubagent-skillsSecurity-validated
gohypergiantagent-skillsEnterprise-grade
openserv-labsskillsMulti-agent workflows

Step 2: Assess — Security Vetting

Every skill in the digest must carry a trust signal. This is non-negotiable.

Why

  • Snyk ToxicSkills (Feb 2026): 36.8% of 3,984 skills had security flaws; 76 confirmed malicious.
  • ClawHavoc: mass malicious upload to ClawHub — credential theft, backdoors, exfiltration.
  • OWASP AST02: Supply Chain Compromise is a top-10 agentic skill risk.
  • Skills have full agent access — filesystem, shell, credentials, network.

Trust Tiers

TierLabelCriteria
SOfficialFrom Anthropic, Vercel, or platform vendor; audited
AHigh TrustKnown publisher, high adoption, security grade A-B, transparent code
BModerateEstablished publisher, decent adoption, no red flags
CCautionNew/low-adoption, ungraded — review SKILL.md before installing
DRiskyUnknown publisher, suspicious patterns — do not recommend

What to Check

  • Publisher: Known org? Account age? Other repos?
  • Registry grade: A-F from AgentSkillsHub or Loaditout?
  • Code: Any curl/wget/eval/exec to unknown URLs? Base64? Encoded payloads?
  • Dependencies: Installs obscure npm/pip packages?
  • Permissions: Requests Bash/network/file access proportional to its purpose?
  • Adoption: Real install counts, stars, community feedback?

Rule: Never recommend tier D. Always warn on tier C. Quick Install section only includes tier A+.

Step 3: Categorize

Use broad categories — skills are not limited to coding:

Development | AI/ML | Productivity | Web & Browser | DevOps & Cloud | Data & Analytics | DeFi & Finance | Marketing & Content | Customer Support | Security | Communication | Science & Research | Education | Design & Media | Blockchain & Web3 | Utility

A skill can span multiple categories. Don't force-fit.

Step 4: Generate Digest

Output the following structure. This is the deliverable — designed to be copy-pasted as-is into Slack, Lark, wiki, or blog.

# Skill Scout Digest

> {date} | Scanned: skills.sh, ClawHub, AgentSkillsHub, Loaditout, LobeHub, OpenForge, GitHub

---

## Ecosystem Pulse

{3-5 sentences on the current state: total skills across registries, growth trend, any platform news, notable shifts in categories or adoption patterns, recent security events}

---

## Recommended Skills

Vetted picks for team adoption. Security tier A or above.

### 1. {skill-name}
> {one-line description}

| | |
|---|---|
| Publisher | {org/repo} |
| Category | {categories} |
| Adoption | {installs} installs / {stars} stars |
| Security | **{tier}** — {one-line justification} |
| Agents | Claude Code, Cursor, Codex, ... |
| Install | `{command}` |

{2-3 sentences: what it does, why it's worth adopting, who benefits}

---

(Repeat for 5-8 top picks across different categories)

---

## Rising — Worth Watching

New or fast-growing skills not yet broadly adopted, but showing momentum:

| Skill | Publisher | Category | Adoption | Security | Why Watch |
|-------|-----------|----------|----------|----------|-----------|
| {name} | {org} | {cat} | {n} | {tier} | {one-line reason} |

---

## Landscape

### By Category

| Category | Trending Skill | Registries Active |
|----------|---------------|-------------------|
| Development | {name} | skills.sh, Loaditout |
| AI / ML | {name} | ClawHub, LobeHub |
| DeFi & Finance | {name} | OpenForge |
| Productivity | {name} | LobeHub, skills.sh |
| ... | ... | ... |

### Platform Health

| Registry | Scale | Security Posture | Trend |
|----------|-------|-----------------|-------|
| skills.sh | {n} skills | No built-in grading | {growing/stable/...} |
| ClawHub | {n} skills | Post-ClawHavoc improvements | {observation} |
| AgentSkillsHub | {n} skills | A-F grading on all entries | {observation} |
| Loaditout | {n} entries | Security grades + MCP support | {observation} |
| LobeHub | {n} skills | Community ratings | {observation} |

---

## Security Radar

### Recent Incidents & Advisories
{Any new supply chain issues, malicious skill takedowns, CVEs, or platform policy changes}

### Install Safety Checklist
1. `uvx mcp-scan@latest --skills` — scan before installing
2. Read the SKILL.md — look for shell commands to unknown URLs, base64, encoded payloads
3. Check the publisher — account age, other repos, community presence
4. Pin versions — use commit SHAs, not `@latest`
5. Least privilege — does the skill need the permissions it requests?

---

## Quick Install

Copy-paste to try the top picks (tier A+ only):

\```bash
{install command 1}
{install command 2}
{install command 3}
\```

---

*Generated by [skill-scout](https://github.com/caoergou/erics-skills) — the ecosystem radar for AI agent skills*

Step 5: Follow-up

---

## Next

1. **Install** — which skill(s) to set up
2. **Deep dive** — fetch full SKILL.md + security review for a specific skill
3. **Compare** — side-by-side on 2-3 skills
4. **Save** — export this digest as a .md file
5. **Audit** — scan your currently installed skills with mcp-scan

Rules

  • Use mcp__exa__web_search_exa for all web searches (never built-in search)
  • Fetch from sources in parallel for speed
  • Every skill must have a trust tier — no exceptions
  • Never recommend tier D; always warn on tier C
  • Don't fabricate data — if a source is down, note the gap
  • Cover all domains, not just coding
  • Note data freshness — when was it last checked
  • For requirement-based search, redirect to find-skills

Keep looking

Skills are one crate of 328,083. Ordering is by how many stacks a row turns up in, so the top of any crate is what has actually been picked rather than what has the most stars.