AGIStoreAGIStore
← Back to Blog
·AGI Store
ai-agentsclaude-codeagent-skillsdeveloper-toolsmarketplace-analysis

AI Agent Skills in 2026: The Good, The Bad, and The 46% That Are Duplicates

If you've used Claude Code, Cursor, or Codex CLI recently, you've seen the explosion: 900,000+ agent skills across five major marketplaces. From "PR Reviewer" to "Docker Compose Generator," there's a skill for everything.

But here's the uncomfortable truth: 46% are duplicates, 9% are security risks, and most don't work well with your codebase.

After analyzing the ecosystem and testing dozens of skills, here's what actually matters.


The 5 Major Marketplaces (June 2026)

| Marketplace | Skills | Approach |

|---|---|---|

| SkillsMP | 364,000+ | Auto-scraped from GitHub, mixed quality |

| skills.sh | 100,000+ | Open registry, 15+ agent support |

| LobeHub | 298,000+ | Large catalog, Claude + Codex + ChatGPT |

| ClawHub | 10,000+ | Free + paid, creators earn €600–20K/month |

| AGI Store | 33+ | Curated, security-reviewed, bilingual (EN/ZH) |

The difference? Volume vs. curation. SkillsMP has everything — including 46% duplicates and known malware. Curated platforms exist because developers need quality, not quantity.


The 3 Problems Nobody Talks About

1. Token Bloat Is Real

A top-1% skill can exceed 100,000 tokens just in instructions. Load 3-4 of those and your context window is full before you write a single line of code. One Reddit engineer tested 47 skills and removed 40 within a week.

2. Skills Don't Know Your Codebase

Generic marketplace skills give generic advice. A deploy skill that doesn't know your smoke test endpoint wastes more time than it saves. Custom skills for your workflow > marketplace skills for everything else.

3. SKILL.md Is an Attack Surface

OWASP published a formal Agentic Skills Top 10 threat taxonomy. 36.8% of scanned skills had security flaws. Three documented attack vectors:

- Prompt injection that exfiltrates env variables

- Base64-encoded credential theft

- Dynamic payloads that change after review

Always read the raw SKILL.md before installing. Look for curl, eval, base64, or external code downloads.

What Actually Works: A Decision Framework

Always Install (7 skills)

- Superpowers — dev lifecycle orchestration (TDD, debugging, code review)

- Simplify — focused code refactoring

- Frontend Design (Anthropic) — UI/UX patterns

- Document Skills (Anthropic) — real PDF/DOCX/XLSX generation

- Planning with Files — persistent task memory

- CI Auditor — pipeline security audit

- Python Expert — 66 specialized Python skills

Install for Your Stack

- Vercel Labs — Web Design Guidelines (133K weekly installs)

- Microsoft — .NET + Azure skills

- HashiCorp — Terraform agent skills

- Google Workspace (March 2026) — 50+ APIs

Cherry-Pick (Not Mega-Collections)

Never install 1,234-skill bundles. The token overhead isn't worth it. Pick 3-5 that solve a specific problem for your workflow.


The Supply-Demand Mismatch

Here's the most telling stat: 54.7% of marketplace skills are software engineering tools (git wrappers, linters, code generators). But the #1 most-installed category is Web Search — only 1.4% of supply.

Builders are building for themselves. Users want connectors, research tools, and practical utilities. This gap is where the next wave of successful skills will come from.


This analysis was conducted by the AGI Store research team. AGI Store is a curated marketplace for production-ready AI agent skills with built-in security review. Visit agistore.dev or browse skills at our marketplace.

Want to discover more production-ready AI agent skills?

Browse AGI Store Skills