Vercel’s npx skills add command installs agent skills from GitHub repos into Claude Code, Cursor, GitHub Copilot, and other Agent Skills-standard tools. Snyk ToxicSkills research (February 2026) scanned 3,984 public registry skills: 13.4% critical vulnerabilities, 76 confirmed malicious payloads including base64-encoded AWS credential theft and jailbreak attempts to disable safety mechanisms.
The vercel-labs/skills repository and skills.sh directory have become a de facto package manager for AI agent capabilities. Developers should treat skills like untrusted code — review before install, prefer official sources (vercel-labs, anthropics), and run security scans before deployment.