Agent Skills vs MCP vs Plugins: What Each Is and When to Use It
An agent skill is a SKILL.md folder an agent loads on demand; MCP is a live protocol to tools and data; a plugin bundles both. What to use when.
Guides, roundups and security reviews for building, sharing and installing Claude Code skills — plus what changes when the same skill runs in Cursor or Windsurf.
A skill is a folder of instructions an AI coding agent loads before it starts work: a SKILL.md describing when to apply it, plus whatever reference files, scripts and examples the agent needs to follow it. Claude Code reads them, and so do Cursor, Windsurf, and the other agents that adopted the same convention — which is why a well-written skill is portable across tools in a way a prompt pasted into a chat window never is.
The articles below cover the whole lifecycle: what separates a skill that changes how an agent writes code from one that restates the official docs, how to publish and share one, and what to check before you install someone else's. Every skill in the SkillSafe registry is scanned before it ships, and the roundups here quote directly from the files rather than ranking by install count.
35 articles in this guide
An agent skill is a SKILL.md folder an agent loads on demand; MCP is a live protocol to tools and data; a plugin bundles both. What to use when.
npx skills add installs a skill folder into every agent directory it detects. The exact syntax, the 79 agent paths, and the check to run before you install.
MCP is not safe by default. Twelve checks, by phase, for vetting an MCP server before install and constraining it at the call, in flight and on update.
Turn a skill into a browser app in two API calls: compose the skills into one prompt, then design a frontend for the goal. Apps are private until you publish.
One command installs a registry skill on every machine you use, into each agent's own directory, verified against the publisher's SHA-256 tree hash.
Create a share link on a saved version, append ?md, and one GET returns the whole SKILL.md plus provenance and install commands. No account, no install.
Where to sell AI agent skills in 2026: SkillSafe (metered runs, 0% on your markup), skills.sh (reach), GitHub (source), Gumroad-style stores (10% + $0.50).
Save the skill, pass the scan, ship it as a hosted app, set a markup of 0-100% per run and keep all of it. Worked numbers, plus the cash-out rules.
Save the skill, give your agent one deploy prompt, get a live app at your-slug.skillsafe.ai. No server, no auth code, no billing integration. Five steps.
Deploy any SkillSafe skill as a hosted app at your-slug.skillsafe.ai: sign-in, credit billing, storage and models included. No servers, no Stripe, no auth code.
AI SkillSafe is a macOS, Windows and Linux app that browses, edits, converts and verifies the skills, agents and commands your AI tools read from disk.
10 DevOps and CI/CD skills installed and scored out of 50. A 1,004-line Docker hardening playbook leads at 45/50; four more cover pipelines and rollout.
We scored 15 CSS and design skills out of 50. @wshobson/responsive-design leads at 44/50 on container queries, fluid typography and CSS Grid.
10 data analysis skills installed and scored out of 50. Three tie at 42/50: a 428-line dashboard playbook, a 14-row chart guide, a 3-script CSV toolkit.
Five of 11 Rust and Go skills we installed are worth using. Apollo's 2,430-line Rust handbook scores 45/50 — full scored comparison and sources.
11 AI/ML skills installed and scored out of 50. @wshobson/rag-implementation leads at 44/50 with five advanced retrieval patterns, including hybrid search.
We read 10 cloud infrastructure skills and scored five out of 50. Terraform state migration and Cloudflare's 12 Workers anti-patterns tie at 43/50.
The 5 best Next.js skills for Claude Code, Cursor and Windsurf, scored out of 50. Top pick: @vercel-labs/next-best-practices at 45/50.
We scored 8 git workflow skills out of 50. Five deliver: rebase playbooks, safety-gated branch cleanup, changelog pipelines. Winner: git-advanced-workflows.
13 API skills installed and scored out of 50. The top five ship 25 files across 7 frameworks, RFC 9457 agent-facing errors, and Apollo's schema rules.
18 security auditing skills installed and scored out of 50. The top five ship 146 vulnerability vectors, 11 language footgun guides and live dependency checks.
13 SQL and database skills installed and scored out of 50. The top five ship 33 prioritized Postgres rules, EXPLAIN analysis and zero-downtime migrations.
Five of 12 TypeScript skills made the cut. @mcollina/typescript-magician leads at 45/50 with 14 rule files. Here is what the other seven got wrong.
We read 11 documentation skills and scored five out of 50. Anthropic's doc co-authoring and React's 885-line reference style guide tie at 43/50.
We scored 11 performance skills out of 50. Vercel's 64-rule react-best-practices wins at 47/50; Callstack's 6,388-line React Native guide takes 45/50.
We scored 14 refactoring skills out of 50. GitHub's 10-smell refactor skill wins at 43/50; Dify's complexity-scoring React skill takes 42/50.
We installed and scored 23 code review skills out of 50. @sanyuan0704/code-review-expert leads at 42/50 with a 7-step workflow and P0-P3 severity.
Five of 17 React skills scored 42/50 or better. @vercel-labs/next-best-practices leads at 46/50 with 20 reference files. Here is what each one fixes.
Five of 18 testing skills scored 40/50 or better. A 61-file Playwright library leads at 46/50. What each one enforces and which framework it fits.
We installed and scored 20 Python skills. These 5 deliver — from 736 lines of async patterns to Sentry's zero-false-positive Django auditor.
Snyk scanned 3,984 AI agent skills: 36.82% had a security flaw, 13.4% a critical one, 76 carried confirmed malware and 8 were still live at publication.
Claude Code skills run with your files, shell and credentials. ClawHavoc put 1,184 malicious skills in one registry. How to check one before you install.
A demo is a replayable agent session pinned to one skill version. 2,625 exist across 30,433 SkillSafe skills. How to record, upload and pin one.
Skills can rewrite themselves from real usage: a forked sub-agent runs, the main agent observes, edits the file, and saves a new immutable version.
Koi Security found 341 malicious skills in 2,857 listings. SkillSafe scans before sharing, re-scans on install, and blocks archives that changed in between.