Agent Skills vs MCP vs Plugins: What Each Is and When to Use It
An agent skill is a SKILL.md folder an agent loads on demand; MCP is a live protocol to tools and data; a plugin bundles both. What to use when.
Articles about AI skill security, coding tool tips, and best practices.
An agent skill is a SKILL.md folder an agent loads on demand; MCP is a live protocol to tools and data; a plugin bundles both. What to use when.
npx skills add installs a skill folder into every agent directory it detects. The exact syntax, the 79 agent paths, and the check to run before you install.
MCP is not safe by default. Twelve checks, by phase, for vetting an MCP server before install and constraining it at the call, in flight and on update.
ID Photo Maker crops a portrait to the official size for 75 passport, visa and ID documents and prints a 4 x 6 or A4 sheet, entirely inside your browser tab.
Turn a skill into a browser app in two API calls: compose the skills into one prompt, then design a frontend for the goal. Apps are private until you publish.
A skill needs an agent to run it. Deploy the skill as an app, then schedule the app: cron in your own time zone, output emailed or POSTed, no server to run.
One command installs a registry skill on every machine you use, into each agent's own directory, verified against the publisher's SHA-256 tree hash.
Create a share link on a saved version, append ?md, and one GET returns the whole SKILL.md plus provenance and install commands. No account, no install.
Set allow_fork and anyone can read a SkillSafe app's whole source — prompt and files — then clone it in one call. Pricing, keys and user data never copy.
SkillSafe now has one storage number per account: 50 MB Free, 10 GB on the relaunched $9 Pro plan, 10 GB per Team seat pooled, plus $10 of seat credit.
Where to sell AI agent skills in 2026: SkillSafe (metered runs, 0% on your markup), skills.sh (reach), GitHub (source), Gumroad-style stores (10% + $0.50).
Save the skill, pass the scan, ship it as a hosted app, set a markup of 0-100% per run and keep all of it. Worked numbers, plus the cash-out rules.
A run costs the model's list price plus 10% to the platform and the creator's markup on the same base, in credits at $1 = 10,000. Worked examples inside.
Stripe's 30c fixed fee is 31x a typical $0.0096 AI run. Meter in credits instead: $1 = 10,000 credits, a 0-100% markup you keep in full, zero billing code.
Save the skill, give your agent one deploy prompt, get a live app at your-slug.skillsafe.ai. No server, no auth code, no billing integration. Five steps.
No single winner: Streamlit for Python data apps, Spaces for GPU model demos, custom GPTs for ChatGPT-native bots, SkillSafe Apps for metered agent skills.
Deploy any SkillSafe skill as a hosted app at your-slug.skillsafe.ai: sign-in, credit billing, storage and models included. No servers, no Stripe, no auth code.
Arcade.dev raised $60M in June 2026 for an agent authorization layer. What scoped permissions, MCP tool policy and audit trails mean for your agent stack.
Agentjacking hijacks AI coding agents with a fake Sentry error. Tenet found 2,388 exposed orgs, 100+ agents running attacker code, an 85% success rate.
An IETF Internet-Draft names 6 recurring MCP vulnerability classes and states that the MCP specification defines no normative security requirements.
An AI agent provisioned five AWS instances to port-scan DN42 and ran up $6,531.30 in about 24 hours. Cost, scope and rate are tool permissions, not prompt text.
Varonis and Imperva tested OpenClaw agents in June 2026: 2 of 4 phishing scenarios leaked live secrets. Identity-bound tool permissions are the fix.
An Agent Bill of Materials lists every skill, plugin, MCP server, credential and paired device an agent can reach. OpenClaw's ClawJacked bug is why you need one.
Cisco Cloud Control puts AI agents, MCP connectors and a 50-partner tool marketplace inside infrastructure operations. What admission control that now requires.
Vercel's skills.sh API exposes 600,000+ agent skills to any tool holding an OIDC token. Pin the content hash, not the name, before you let an agent install one.
VIPER-MCP scanned 39,884 MCP server repos and confirmed 106 zero-days, 67 with CVE IDs. Agent tools need code-level taint analysis, not trust prompts.
Microsoft's Agent Control Specification evaluates agent policy at 8 intervention points and returns 1 of 5 verdicts: allow, warn, deny, escalate, transform.
The NSA's May 2026 MCP guidance treats agent tooling as infrastructure: inventory every server, verify tool changes, and scan before trust drifts.
Ruleset v2026.06.05 adds five rules for a publisher family targeting ~/.claude and fixes eight noisy patterns. Stage 2 now reads ~6 findings per skill, not ~15.
OX Security found a remote code execution design flaw in MCP's official SDKs: 10 CVEs, 30+ disclosures, 7,000+ exposed servers. Treat MCP servers as code.
A Hugging Face repo typosquatted OpenAI's Privacy Filter, hit #1 trending on 244K downloads in 18 hours, then ran a Rust infostealer. The full attack chain.
AI SkillSafe is a macOS, Windows and Linux app that browses, edits, converts and verifies the skills, agents and commands your AI tools read from disk.
10 DevOps and CI/CD skills installed and scored out of 50. A 1,004-line Docker hardening playbook leads at 45/50; four more cover pipelines and rollout.
We scored 15 CSS and design skills out of 50. @wshobson/responsive-design leads at 44/50 on container queries, fluid typography and CSS Grid.
10 data analysis skills installed and scored out of 50. Three tie at 42/50: a 428-line dashboard playbook, a 14-row chart guide, a 3-script CSV toolkit.
Five of 11 Rust and Go skills we installed are worth using. Apollo's 2,430-line Rust handbook scores 45/50 — full scored comparison and sources.
11 AI/ML skills installed and scored out of 50. @wshobson/rag-implementation leads at 44/50 with five advanced retrieval patterns, including hybrid search.
We read 10 cloud infrastructure skills and scored five out of 50. Terraform state migration and Cloudflare's 12 Workers anti-patterns tie at 43/50.
The 5 best Next.js skills for Claude Code, Cursor and Windsurf, scored out of 50. Top pick: @vercel-labs/next-best-practices at 45/50.
Claude Mythos Preview found zero-days in every major OS and browser, one of them 27 years old, for under $50 a bug. What defenders should change now.
We scored 8 git workflow skills out of 50. Five deliver: rebase playbooks, safety-gated branch cleanup, changelog pipelines. Winner: git-advanced-workflows.
13 API skills installed and scored out of 50. The top five ship 25 files across 7 frameworks, RFC 9457 agent-facing errors, and Apollo's schema rules.
18 security auditing skills installed and scored out of 50. The top five ship 146 vulnerability vectors, 11 language footgun guides and live dependency checks.
13 SQL and database skills installed and scored out of 50. The top five ship 33 prioritized Postgres rules, EXPLAIN analysis and zero-downtime migrations.
Five of 12 TypeScript skills made the cut. @mcollina/typescript-magician leads at 45/50 with 14 rule files. Here is what the other seven got wrong.
We read 11 documentation skills and scored five out of 50. Anthropic's doc co-authoring and React's 885-line reference style guide tie at 43/50.
We scored 11 performance skills out of 50. Vercel's 64-rule react-best-practices wins at 47/50; Callstack's 6,388-line React Native guide takes 45/50.
We scored 14 refactoring skills out of 50. GitHub's 10-smell refactor skill wins at 43/50; Dify's complexity-scoring React skill takes 42/50.
We installed and scored 23 code review skills out of 50. @sanyuan0704/code-review-expert leads at 42/50 with a 7-step workflow and P0-P3 severity.
Five of 17 React skills scored 42/50 or better. @vercel-labs/next-best-practices leads at 46/50 with 20 reference files. Here is what each one fixes.
Five of 18 testing skills scored 40/50 or better. A 61-file Playwright library leads at 46/50. What each one enforces and which framework it fits.
We installed and scored 20 Python skills. These 5 deliver — from 736 lines of async patterns to Sentry's zero-false-positive Django auditor.
Snyk scanned 3,984 AI agent skills: 36.82% had a security flaw, 13.4% a critical one, 76 carried confirmed malware and 8 were still live at publication.
MCP tool poisoning hides attacker instructions in tool description metadata your model reads and your UI never shows. How it works, and how to detect it.
Langflow's CVSS 9.3 unauthenticated RCE was exploited in the wild 20 hours after disclosure, with no public PoC. Three LangChain and LangGraph CVEs followed.
TeamPCP hid a credential stealer in a WAV file inside telnyx 4.87.1 on PyPI, using tokens stolen from litellm three days earlier. Why the cascade evades review.
Claude Code skills run with your files, shell and credentials. ClawHavoc put 1,184 malicious skills in one registry. How to check one before you install.
TeamPCP pushed a credential stealer into litellm 1.82.7 and 1.82.8 on PyPI via a compromised Trivy action. What it did, and why AI skills are next.
SkillJect poisons agent skills and averages 80.7% attack success on Claude Code. Four skill scanners caught it 61.5% of the time. The 4 rules we shipped.
A demo is a replayable agent session pinned to one skill version. 2,625 exist across 30,433 SkillSafe skills. How to record, upload and pin one.
ClawHavoc was a January 2026 poisoning campaign on ClawHub: 1,184 malicious agent skills from 12 author IDs, most delivering the AMOS macOS stealer.
Three registry security models - reactive moderation, install-time scanning, and dual-side verification with a tree hash - and the attack each one misses.
Skills can rewrite themselves from real usage: a forked sub-agent runs, the main agent observes, edits the file, and saves a new immutable version.
Koi Security found 341 malicious skills in 2,857 listings. SkillSafe scans before sharing, re-scans on install, and blocks archives that changed in between.
Dual-side verification scans a shared AI skill twice, once by the publisher and once by you, then compares both reports and a SHA-256 tree hash before install.