Skip to main content
AI & Full-Stack·10 min read

Secure Agent Skills in 2026: Treat SKILL.md as Executable Code

AI chat can hand you a poisoned download link. A restored backup can reinstall malware through a SKILL.md. Production security model for Agent Skills and coding-agent config on TypeScript and Next.js teams.

By Mussawar Hayat

Skills Are Code Now

In late August 2026 a widely shared developer report made the same point twice. First, an AI chat recommended a download link for a transcription app. The site was a copycat. Second, after a clean wipe, a backup contained a SKILL.md that mimicked a personal writing-style skill and instructed the agent to fetch the payload again whenever the skill loaded.

Models cannot verify URLs. Agent files look like notes and behave like code. Anthropic warns that malicious skills can introduce vulnerabilities, exfiltrate data, or drive unintended actions. The Agent Skills spec at agentskills.io allows a scripts/ directory next to SKILL.md.

What You Will Learn

  • Why SKILL.md belongs in the same threat model as shell scripts
  • Review checklist before third-party skill install
  • Safe handling of AI-suggested install commands
  • Repo layout, CI tripwires, and restore hygiene

1. The Problem: Notes That Execute

A skill is a folder with SKILL.md and optional scripts/. Compatible agents inject the body into context when the description matches. Three failure modes: unverified install advice, skill or memory poisoning, and restore replay from backups or dotfiles.

Map this to OWASP LLM01 (prompt injection) and Agentic risks: goal hijack, tool misuse, privilege abuse, and memory poisoning.

2. Official Warnings

  • Anthropic: trusted sources only; audit scripts and network calls.
  • Claude Code: least privilege, sandbox, working-directory boundary.
  • agentskills.io: scripts are meant to run.

3. Review Checklist

  • Verify author and canonical repo without chat links.
  • Pin commits or tags.
  • Read every file. Search for curl, wget, fetch, .env, SSH keys, silent execution.
  • Prefer Markdown-only skills. Reject opaque binaries.
  • Keep descriptions narrow so skills do not activate on every prompt.

4. AI Install Commands

Never pipe remote scripts from chat. Reconstruct installs from official domains you type yourself. Prefer npm i package --ignore-scripts until you review files. Pin versions. First-run unknown CLIs in a throwaway VM.

5. Production Layout

Keep team skills under .agents/skills in the repo so they go through pull request. Skills must not read .env or phone home unless the host is named in the PR. Auto mode is not allowed on machines with production secrets.

6. Restore Hygiene

Treat ~/.claude, ~/.codex, ~/.cursor, and .agents as executable config. Diff before restore. Read every skill, hook, and MCP entry. After a bad install: disconnect secrets, rotate tokens, rebuild from known-good sources.

7. Permissions and Agency

  • Supervised tool approval on production machines
  • Filesystem and network sandbox when available
  • Allowlist commands; least-privilege MCP tokens
  • Separate identities for experiments vs production

8. FAQ

Is Markdown really executable?

The agent is the interpreter. With shell tools enabled, skill instructions become actions.

Does sandboxing fix this?

It shrinks blast radius. Review is still required.

Repo or home directory?

Team conventions in the repo via PR. Inspect personal skills after any incident.

9. Summary

If an agent will load it, treat it as code — SKILL.md included. Review third-party skills like dependencies. Reconstruct install commands from official domains you type yourself.


Building agent-safe Next.js systems?

Get in touch · Services

Related: Agent Skills guide · Grok Bot guardrails.

Frequently Asked Questions

Is a Markdown skill really executable?

The file is text. The agent is the interpreter. Once the skill body is in context, the agent follows it with whatever tools you enabled — including a terminal. Bundled scripts in scripts/ are ordinary executables.

Are official Matt Pocock or Anthropic skills safe by default?

They are a better starting point than anonymous zips, and they should still be pinned and reviewed when they change. Trust the commit you read, not the brand in the abstract.

Does sandboxing make skills safe?

Sandboxing shrinks blast radius. It does not stop a skill from leaking whatever the sandbox can still read, or from asking you to disable the sandbox.

Should skills live in the repo or in the home directory?

Team conventions belong in the repo so they go through pull request. Personal cross-project skills can live in the home directory, but inspect them first after any incident.

What should I do after a bad install command?

Disconnect the machine from secrets first. Rotate tokens that lived on it. Do not restore agent config until every skill, hook, and MCP entry is read.