Secure Agent Skills in 2026: Treat SKILL.md as Executable Code
AI chat can hand you a poisoned download link. A restored backup can reinstall malware through a SKILL.md. Production security model for Agent Skills and coding-agent config on TypeScript and Next.js teams.
By Mussawar Hayat
Skills Are Code Now
In late August 2026 a widely shared developer report made the same point twice. First, an AI chat recommended a download link for a transcription app. The site was a copycat. Second, after a clean wipe, a backup contained a SKILL.md that mimicked a personal writing-style skill and instructed the agent to fetch the payload again whenever the skill loaded.
Models cannot verify URLs. Agent files look like notes and behave like code. Anthropic warns that malicious skills can introduce vulnerabilities, exfiltrate data, or drive unintended actions. The Agent Skills spec at agentskills.io allows a scripts/ directory next to SKILL.md.
What You Will Learn
- Why SKILL.md belongs in the same threat model as shell scripts
- Review checklist before third-party skill install
- Safe handling of AI-suggested install commands
- Repo layout, CI tripwires, and restore hygiene
1. The Problem: Notes That Execute
A skill is a folder with SKILL.md and optional scripts/. Compatible agents inject the body into context when the description matches. Three failure modes: unverified install advice, skill or memory poisoning, and restore replay from backups or dotfiles.
Map this to OWASP LLM01 (prompt injection) and Agentic risks: goal hijack, tool misuse, privilege abuse, and memory poisoning.
2. Official Warnings
- Anthropic: trusted sources only; audit scripts and network calls.
- Claude Code: least privilege, sandbox, working-directory boundary.
- agentskills.io: scripts are meant to run.
3. Review Checklist
- Verify author and canonical repo without chat links.
- Pin commits or tags.
- Read every file. Search for curl, wget, fetch, .env, SSH keys, silent execution.
- Prefer Markdown-only skills. Reject opaque binaries.
- Keep descriptions narrow so skills do not activate on every prompt.
4. AI Install Commands
Never pipe remote scripts from chat. Reconstruct installs from official domains you type yourself. Prefer npm i package --ignore-scripts until you review files. Pin versions. First-run unknown CLIs in a throwaway VM.
5. Production Layout
Keep team skills under .agents/skills in the repo so they go through pull request. Skills must not read .env or phone home unless the host is named in the PR. Auto mode is not allowed on machines with production secrets.
6. Restore Hygiene
Treat ~/.claude, ~/.codex, ~/.cursor, and .agents as executable config. Diff before restore. Read every skill, hook, and MCP entry. After a bad install: disconnect secrets, rotate tokens, rebuild from known-good sources.
7. Permissions and Agency
- Supervised tool approval on production machines
- Filesystem and network sandbox when available
- Allowlist commands; least-privilege MCP tokens
- Separate identities for experiments vs production
8. FAQ
Is Markdown really executable?
The agent is the interpreter. With shell tools enabled, skill instructions become actions.
Does sandboxing fix this?
It shrinks blast radius. Review is still required.
Repo or home directory?
Team conventions in the repo via PR. Inspect personal skills after any incident.
9. Summary
If an agent will load it, treat it as code — SKILL.md included. Review third-party skills like dependencies. Reconstruct install commands from official domains you type yourself.
Building agent-safe Next.js systems?
Related: Agent Skills guide · Grok Bot guardrails.
Frequently Asked Questions
Is a Markdown skill really executable?
The file is text. The agent is the interpreter. Once the skill body is in context, the agent follows it with whatever tools you enabled — including a terminal. Bundled scripts in scripts/ are ordinary executables.
Are official Matt Pocock or Anthropic skills safe by default?
They are a better starting point than anonymous zips, and they should still be pinned and reviewed when they change. Trust the commit you read, not the brand in the abstract.
Does sandboxing make skills safe?
Sandboxing shrinks blast radius. It does not stop a skill from leaking whatever the sandbox can still read, or from asking you to disable the sandbox.
Should skills live in the repo or in the home directory?
Team conventions belong in the repo so they go through pull request. Personal cross-project skills can live in the home directory, but inspect them first after any incident.
What should I do after a bad install command?
Disconnect the machine from secrets first. Rotate tokens that lived on it. Do not restore agent config until every skill, hook, and MCP entry is read.
Related guides
How to run Octomind AI agents against a Next.js 16 app in production. Covers agent-generated Playwright tests, TypeScript config, CI integration on preview deploys, auth handling, flake control, and when autonomous e2e agents beat hand-written suites.
Claude Code Mods in TypeScript: Production Guardrails for Next.js Teams (2026)Anthropic shipped Claude Code mods on October 1, 2026. Build a TypeScript plugin that blocks force-pushes, redacts secrets from tool output, and asks before destructive shell commands, without replacing human review.
Production Evals for Coding Agents in TypeScript and Next.js (2026)Code generation is cheap. Knowing the agent is right is not. This guide shows how to score TypeScript and Next.js coding agents with fixture tasks, deterministic checks, LLM judges used only where needed, merge gates, and a CI harness you can run without a human watching every diff.
