<?xml version="1.0" encoding="UTF-8"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>SkillSafe Blog</title><description>AI skill security, coding tool tips, and best practices for building verified skills.</description><link>https://skillsafe.ai/</link><atom:link href="https://skillsafe.ai/rss.xml" rel="self" type="application/rss+xml"/><item><title>Best AI Skills for DevOps and CI/CD [2026]</title><link>https://skillsafe.ai/blog/best-ai-devops-cicd-skills-2026/</link><guid isPermaLink="true">https://skillsafe.ai/blog/best-ai-devops-cicd-skills-2026/</guid><description>Top 5 DevOps CI/CD skills from our scored review — Docker security playbooks, Argo Rollouts canary configs, and a production-ready blue-green script.</description><pubDate>Wed, 15 Apr 2026 00:00:00 GMT</pubDate></item><item><title>Best AI/ML Development Skills and Tools [2026]</title><link>https://skillsafe.ai/blog/best-ai-ml-development-skills-2026/</link><guid isPermaLink="true">https://skillsafe.ai/blog/best-ai-ml-development-skills-2026/</guid><description>Top 5 AI/ML development skills from our scored review — RAG architectures, prompt engineering patterns, LLM debugging frameworks, and production guidance.</description><pubDate>Wed, 15 Apr 2026 00:00:00 GMT</pubDate></item><item><title>Best AI CSS and Design Skills [2026]</title><link>https://skillsafe.ai/blog/best-ai-css-design-skills-2026/</link><guid isPermaLink="true">https://skillsafe.ai/blog/best-ai-css-design-skills-2026/</guid><description>We installed and scored 15 CSS and design skills. These 5 stood out — from fluid typography cookbooks to a 99-rule UX checklist with a built-in CLI.</description><pubDate>Wed, 15 Apr 2026 00:00:00 GMT</pubDate></item><item><title>Best AI Data Analysis Skills for Developers [2026]</title><link>https://skillsafe.ai/blog/best-ai-data-analysis-skills-2026/</link><guid isPermaLink="true">https://skillsafe.ai/blog/best-ai-data-analysis-skills-2026/</guid><description>We installed and scored 10 data analysis skills. These 5 stood out — from a chart-selection encyclopedia to a three-script CSV profiling toolkit.</description><pubDate>Wed, 15 Apr 2026 00:00:00 GMT</pubDate></item><item><title>Best AI Skills for Systems Languages: Rust and Go [2026]</title><link>https://skillsafe.ai/blog/best-ai-systems-languages-rust-go-2026/</link><guid isPermaLink="true">https://skillsafe.ai/blog/best-ai-systems-languages-rust-go-2026/</guid><description>We installed and scored 11 systems programming skills. These 5 stood out — from Apollo&apos;s 2,400-line Rust handbook to production Go concurrency patterns.</description><pubDate>Wed, 15 Apr 2026 00:00:00 GMT</pubDate></item><item><title>Top AI Skills for Cloud Infrastructure [2026]</title><link>https://skillsafe.ai/blog/top-ai-cloud-infrastructure-skills-2026/</link><guid isPermaLink="true">https://skillsafe.ai/blog/top-ai-cloud-infrastructure-skills-2026/</guid><description>Top 5 cloud infrastructure skills from our scored review — Terraform state migrations, Cloudflare anti-pattern catalogs, and 4,000+ lines of guidance.</description><pubDate>Wed, 15 Apr 2026 00:00:00 GMT</pubDate></item><item><title>Top AI Skills for Next.js Development [2026]</title><link>https://skillsafe.ai/blog/top-ai-nextjs-skills-2026/</link><guid isPermaLink="true">https://skillsafe.ai/blog/top-ai-nextjs-skills-2026/</guid><description>Top 5 Next.js AI skills from our scored review — including an eval-proven bundle that raised pass rates from 32% to 78% and a 50-line upgrade assistant.</description><pubDate>Wed, 15 Apr 2026 00:00:00 GMT</pubDate></item><item><title>Claude Mythos Found Zero-Days Everywhere. Here&apos;s Your Playbook.</title><link>https://skillsafe.ai/blog/claude-mythos-zero-days-defender-playbook/</link><guid isPermaLink="true">https://skillsafe.ai/blog/claude-mythos-zero-days-defender-playbook/</guid><description>Anthropic&apos;s Mythos Preview discovered zero-days in every major OS and browser. Defenders have months, not years, to adapt. Here&apos;s what to do now.</description><pubDate>Fri, 10 Apr 2026 00:00:00 GMT</pubDate></item><item><title>Best AI Security Auditing Skills for Developers [2026]</title><link>https://skillsafe.ai/blog/best-ai-security-auditing-skills-2026/</link><guid isPermaLink="true">https://skillsafe.ai/blog/best-ai-security-auditing-skills-2026/</guid><description>Top 5 security auditing skills from our scored review — 146 vulnerability vectors, 11 footgun databases, and a real-time GitHub supply chain auditor.</description><pubDate>Tue, 07 Apr 2026 00:00:00 GMT</pubDate></item><item><title>Best AI Skills for Git Workflows [2026]</title><link>https://skillsafe.ai/blog/best-ai-git-workflow-skills-2026/</link><guid isPermaLink="true">https://skillsafe.ai/blog/best-ai-git-workflow-skills-2026/</guid><description>We installed and scored 8 git workflow skills. These 5 stood out — with rebase playbooks, branch cleanup safety gates, and changelog automation pipelines.</description><pubDate>Tue, 07 Apr 2026 00:00:00 GMT</pubDate></item><item><title>Best AI Skills for SQL and Database Development [2026]</title><link>https://skillsafe.ai/blog/best-ai-sql-database-skills-2026/</link><guid isPermaLink="true">https://skillsafe.ai/blog/best-ai-sql-database-skills-2026/</guid><description>We installed and scored 13 database skills. These 5 stood out — with 3,000+ lines of Postgres rules, query optimization patterns, and migration playbooks.</description><pubDate>Tue, 07 Apr 2026 00:00:00 GMT</pubDate></item><item><title>Best AI Skills for API Development [2026]</title><link>https://skillsafe.ai/blog/best-ai-api-development-skills-2026/</link><guid isPermaLink="true">https://skillsafe.ai/blog/best-ai-api-development-skills-2026/</guid><description>Top 5 API development skills from our scored review — a 25-file multi-framework implementation guide and an RFC 9457 error system with agent extensions.</description><pubDate>Tue, 07 Apr 2026 00:00:00 GMT</pubDate></item><item><title>Best AI Skills for TypeScript Development [2026]</title><link>https://skillsafe.ai/blog/best-ai-typescript-skills-2026/</link><guid isPermaLink="true">https://skillsafe.ai/blog/best-ai-typescript-skills-2026/</guid><description>Top 5 TypeScript AI skills from our scored review — a 14-file type system encyclopedia and a spec-to-types converter that writes type guards for you.</description><pubDate>Tue, 07 Apr 2026 00:00:00 GMT</pubDate></item><item><title>Top AI Documentation Tools and Skills [2026]</title><link>https://skillsafe.ai/blog/top-ai-documentation-skills-2026/</link><guid isPermaLink="true">https://skillsafe.ai/blog/top-ai-documentation-skills-2026/</guid><description>Top 5 documentation AI skills from our scored review — structured co-authoring workflows, 885-line reference templates, and ready-to-use README frameworks.</description><pubDate>Tue, 07 Apr 2026 00:00:00 GMT</pubDate></item><item><title>Top AI Performance Optimization Skills [2026]</title><link>https://skillsafe.ai/blog/top-ai-performance-optimization-skills-2026/</link><guid isPermaLink="true">https://skillsafe.ai/blog/top-ai-performance-optimization-skills-2026/</guid><description>We installed and scored 11 performance skills. These 5 stood out -- with 11,000+ lines of profiling rules, optimization patterns, and benchmarking workflows.</description><pubDate>Tue, 07 Apr 2026 00:00:00 GMT</pubDate></item><item><title>Top AI Code Refactoring Skills [2026]</title><link>https://skillsafe.ai/blog/top-ai-refactoring-skills-2026/</link><guid isPermaLink="true">https://skillsafe.ai/blog/top-ai-refactoring-skills-2026/</guid><description>We installed and scored 14 refactoring skills. These 5 stood out — with safety checklists, complexity scoring systems, and 2,900+ lines of refactoring patterns.</description><pubDate>Tue, 07 Apr 2026 00:00:00 GMT</pubDate></item><item><title>Best AI Code Review Tools and Skills [2026]</title><link>https://skillsafe.ai/blog/best-ai-code-review-skills-2026/</link><guid isPermaLink="true">https://skillsafe.ai/blog/best-ai-code-review-skills-2026/</guid><description>We installed and scored 23 code review skills. These 5 stood out — with real checklists, multi-agent workflows, and 1,500+ lines of review patterns.</description><pubDate>Thu, 02 Apr 2026 00:00:00 GMT</pubDate></item><item><title>Best AI Skills for React Development [2026]</title><link>https://skillsafe.ai/blog/best-ai-react-skills-2026/</link><guid isPermaLink="true">https://skillsafe.ai/blog/best-ai-react-skills-2026/</guid><description>We installed and scored 17 React skills. These 5 earned their spot — from Vercel&apos;s 20-file Next.js encyclopedia to a typed state management cookbook.</description><pubDate>Thu, 02 Apr 2026 00:00:00 GMT</pubDate></item><item><title>Best AI Testing and QA Skills for Developers [2026]</title><link>https://skillsafe.ai/blog/best-ai-testing-qa-skills-2026/</link><guid isPermaLink="true">https://skillsafe.ai/blog/best-ai-testing-qa-skills-2026/</guid><description>We installed and scored 18 testing skills. These 5 earned their spot — from a 61-file Playwright encyclopedia to strict TDD enforcement.</description><pubDate>Thu, 02 Apr 2026 00:00:00 GMT</pubDate></item><item><title>Top AI Coding Skills for Python Developers [2026]</title><link>https://skillsafe.ai/blog/top-ai-python-coding-skills-2026/</link><guid isPermaLink="true">https://skillsafe.ai/blog/top-ai-python-coding-skills-2026/</guid><description>We installed and scored 20 Python skills. These 5 deliver — from 736 lines of async patterns to Sentry&apos;s zero-false-positive Django auditor.</description><pubDate>Thu, 02 Apr 2026 00:00:00 GMT</pubDate></item><item><title>ToxicSkills: What the First Large-Scale Agent Skill Audit Found</title><link>https://skillsafe.ai/blog/toxicskills-first-skill-ecosystem-audit/</link><guid isPermaLink="true">https://skillsafe.ai/blog/toxicskills-first-skill-ecosystem-audit/</guid><description>Snyk scanned 3,984 AI agent skills: 36% had security flaws, 534 critical issues, 76 active malware. What this means for developers installing skills.</description><pubDate>Thu, 02 Apr 2026 00:00:00 GMT</pubDate></item><item><title>MCP Tool Poisoning: How Hidden Metadata Hijacks AI Agents</title><link>https://skillsafe.ai/blog/mcp-tool-poisoning-hidden-metadata/</link><guid isPermaLink="true">https://skillsafe.ai/blog/mcp-tool-poisoning-hidden-metadata/</guid><description>MCP tool descriptions are visible to your AI agent but hidden from you. Attackers embed instructions that hijack agent behavior and steal credentials.</description><pubDate>Tue, 31 Mar 2026 00:00:00 GMT</pubDate></item><item><title>Langflow Exploited in 20 Hours: The AI Framework Attack Surface</title><link>https://skillsafe.ai/blog/langflow-ai-framework-attack-surface/</link><guid isPermaLink="true">https://skillsafe.ai/blog/langflow-ai-framework-attack-surface/</guid><description>Langflow&apos;s critical RCE was weaponized in 20 hours. Combined with new LangChain and LangGraph CVEs, AI framework infrastructure is under active attack.</description><pubDate>Sun, 29 Mar 2026 00:00:00 GMT</pubDate></item><item><title>When Trusted Packages Turn Hostile: Cascading Supply Chain Attacks</title><link>https://skillsafe.ai/blog/when-trusted-packages-turn-hostile/</link><guid isPermaLink="true">https://skillsafe.ai/blog/when-trusted-packages-turn-hostile/</guid><description>TeamPCP compromises legitimate packages and cascades through the supply chain via stolen credentials. Why this attack pattern evades detection.</description><pubDate>Sat, 28 Mar 2026 00:00:00 GMT</pubDate></item><item><title>You&apos;re Using Claude Code Skills. Do You Know What&apos;s in Them?</title><link>https://skillsafe.ai/blog/claude-code-skill-security/</link><guid isPermaLink="true">https://skillsafe.ai/blog/claude-code-skill-security/</guid><description>Claude Code skills can read files, run commands, and access credentials. What the skill ecosystem gets wrong about security — and how to protect yourself.</description><pubDate>Fri, 27 Mar 2026 00:00:00 GMT</pubDate></item><item><title>LiteLLM&apos;s PyPI Backdoor: What It Means for the AI Skill Supply Chain</title><link>https://skillsafe.ai/blog/litellm-supply-chain-attack/</link><guid isPermaLink="true">https://skillsafe.ai/blog/litellm-supply-chain-attack/</guid><description>Attackers injected a credential stealer into litellm (95M downloads) via compromised CI/CD. What happened and why AI skills face the same threat.</description><pubDate>Wed, 25 Mar 2026 00:00:00 GMT</pubDate></item><item><title>SkillJect and the Gap in Skill Registry Security</title><link>https://skillsafe.ai/blog/skillject-phase0-scanner/</link><guid isPermaLink="true">https://skillsafe.ai/blog/skillject-phase0-scanner/</guid><description>A new paper achieves 97.5% attack success against Claude Code using poisoned skills. Here&apos;s what we found, and the four detection rules we shipped in response.</description><pubDate>Sun, 15 Mar 2026 00:00:00 GMT</pubDate></item><item><title>Show, Don&apos;t Just Ship: Why Every Skill Needs a Demo</title><link>https://skillsafe.ai/blog/why-demo-your-skill/</link><guid isPermaLink="true">https://skillsafe.ai/blog/why-demo-your-skill/</guid><description>A skill without a demo is a black box. Why recording a real agent session is the highest-leverage thing you can do to earn trust and drive installs.</description><pubDate>Fri, 13 Mar 2026 00:00:00 GMT</pubDate></item><item><title>ClawHavoc: 1,184 Malicious Skills and Why Pre-Install Verification Matters</title><link>https://skillsafe.ai/blog/clawhavoc-post-mortem/</link><guid isPermaLink="true">https://skillsafe.ai/blog/clawhavoc-post-mortem/</guid><description>Post-mortem of ClawHavoc — the largest AI skill supply chain attack on record — and what it reveals about the limits of reactive security models.</description><pubDate>Mon, 09 Mar 2026 00:00:00 GMT</pubDate></item><item><title>Why Scanning Architecture Matters: Comparing Skill Registry Security</title><link>https://skillsafe.ai/blog/scanning-architecture-comparison/</link><guid isPermaLink="true">https://skillsafe.ai/blog/scanning-architecture-comparison/</guid><description>Comparing install-time scanning, reactive moderation, and dual-side verification — and the supply chain attack vectors each security model misses.</description><pubDate>Mon, 09 Mar 2026 00:00:00 GMT</pubDate></item><item><title>Self-Improving Skills: How SkillSafe Skills Get Better With Use</title><link>https://skillsafe.ai/blog/self-improving-skills/</link><guid isPermaLink="true">https://skillsafe.ai/blog/self-improving-skills/</guid><description>SkillSafe skills can improve from real usage feedback. How the observe-improve-save loop works and how to opt your skills into automatic iteration.</description><pubDate>Sun, 01 Mar 2026 00:00:00 GMT</pubDate></item><item><title>Introducing SkillSafe: Why AI Coding Skills Need a Verified Registry</title><link>https://skillsafe.ai/blog/introducing-skillsafe/</link><guid isPermaLink="true">https://skillsafe.ai/blog/introducing-skillsafe/</guid><description>341 malicious AI skills were found on a major registry. SkillSafe scans before sharing, re-verifies on install, and blocks tampered code automatically.</description><pubDate>Sun, 15 Feb 2026 00:00:00 GMT</pubDate></item><item><title>How Dual-Side Verification Protects Against Supply Chain Attacks</title><link>https://skillsafe.ai/blog/how-dual-side-verification-works/</link><guid isPermaLink="true">https://skillsafe.ai/blog/how-dual-side-verification-works/</guid><description>How SkillSafe dual-side verification works: publisher scans, consumer re-scans, and cryptographic tree hashes that detect tampering before install.</description><pubDate>Tue, 10 Feb 2026 00:00:00 GMT</pubDate></item></channel></rss>