2026-10-11 18:04 UTC

xm1k3 claims the released ai-community-skills catalog statically flags risky patterns with file-and-line evidence before installing third-party agent skills, enabling local pre-installation review without executing skill contents.

state: resolvedheat: lowuncertainty: lowknownscott: lowagentic-security agent-skills software-supply-chainxm1k3

What is this?

The case describes ai-community-skills as a released local catalog attributed to xm1k3, with roughly 3,000 community agent skills and a claimed static scan that supplies file-and-line risk findings before installation without executing skill contents. None of the supplied web results directly identifies this project or its creator, so its release, catalog size, and specific capabilities remain unverified here. The snippets establish the surrounding problem—third-party skill instructions can trigger commands, access credentials, or fetch mutable dependencies—and describe other pre-installation scanning approaches, while also reporting limitations of static review.

Why it matters to Scott

The claimed file-and-line risk review repeats Scott’s source-anchored security-triage practice in WordPress Security Review & Plugin Signal Room; the radar already tracks pre-installation skill assessment in SkillPreflight, though not this specific catalog. The supplied material does not verify this release or establish improved detection, adoption in Scott’s projects, or authorisation guarantees of the kind required by his Agent Provenance Stack, so it adds another example rather than a reason to change what he builds or argues.
dev:project.wordpress-security-reviewip:framework.agent-provenance-stackradar:skillpreflight-agent-skill-scoringradar:snyk-agent-scanradar:concept.agent-skillsradar:concept.static-analysis
queries asked of Scott's wikis
  • third-party agent skills installation trust policies
  • coding agent harness pre-execution security gates
  • static risk findings file-line evidence human review
  • agent permissions sandboxing prompt injection
  • supply-chain dependency pinning runtime downloads

Measured heat

no measured readings yet — the hourly heat pass fills this in

How the heat travelled

09-14 16:29 (minted)⭐ origin echo-reconstructedThe released local catalog supports searching and installing community skills with static risk findings, source trust preferences, and expli
xm1k3 on github (echo) · attributed from hn.story.49698971 · published time unknown
—
09-14 15:49first on hacker news · published · lag ?Show HN: Local catalog of 3k agent skills with a static risk scan
xm1k3
—
09-19 03:39first on r/ClaudeAI · published · lag ?How do you handle tool sprawl and untrusted scripts when building with Claude Code and custom agents?
_P_R_I_M_E
—
09-14 15:49amplified on hacker newshn.story.49698971
xm1k3
peak 2 · 0 comments · 23% of case engagement
09-15 22:44amplified on hacker newshn.story.49719882
giuliomagnifico
peak 1 · 0 comments · 12% of case engagement
09-16 05:11amplified on hacker newshn.story.49722348
neogoose
peak 1 · 1 comments · 23% of case engagement
09-18 12:53amplified on hacker newshn.story.49753727
Rinkia
peak 1 · 0 comments · 12% of case engagement
09-19 03:39amplified on r/ClaudeAI 👑reddit.post.1wkbafd
_P_R_I_M_E
peak 1 · 4 comments · 31% of case engagement
09-14 16:20our radar first saw it · lag ?discovery anchor: hn.story.49698971—

Evidence (7) — ⭐ canonical anchor

sourceobjectauthorscorecomments
🟧 hnShow HN: Local catalog of 3k agent skills with a static risk scan
Retrieved article excerpt

Open article · Retrieved 2026-09-14T16:22:52.085897+00:00

[acs](https://github.com/xm1k3/ai-community-skills/blob/main/docs/assets/logo.svg)

# ai-community-skills

All the community Agent Skills scattered across GitHub, in one local catalog. Search them, browse them, and install them into Claude Code, Codex, or Grok, with a risk check on every skill as a bonus.

[npm version](https://www.npmjs.com/package/ai-community-skills)
[license](https://github.com/xm1k3/ai-community-skills/blob/main/LICENSE)
[node](https://camo.githubusercontent.com/dbf1a7cd9fb536bfccd318ea2f02d79d237a1943fd526fa9e0ad4a7de16c4b92/68747470733a2f2f696d672e736869656c64732e696f2f62616467652f6e6f64652d25334525334432302d677265656e)

[ai-community-skills dashboard](https://github.com/xm1k3/ai-community-skills/blob/main/docs/assets/dashboard.jpg)

- [Sources](https://github.com/xm1k3/ai-community-skills#sources)
- Getting started
  - [Installation](https://github.com/xm1k3/ai-community-skills#installation)
  - [Commands](https://github.com/xm1k3/ai-community-skills#commands)
  - [Usage](https://github.com/xm1k3/ai-community-skills#usage)
- [Web dashboard](https://github.com/xm1k3/ai-community-skills#web-dashboard)
- [Risk analysis](https://github.com/xm1k3/ai-community-skills#risk-analysis)
- Reference
  - [Config](https://github.com/xm1k3/ai-community-skills#config)
  - [Updates](https://github.com/xm1k3/ai-community-skills#updates)
- [Disclaimer](https://github.com/xm1k3/ai-community-skills#disclaimer)
- [License](https://github.com/xm1k3/ai-community-skills#license)

## Sources

The curated list of community repositories lives in [`config.json`](https://github.com/xm1k3/ai-community-skills/blob/main/config.json) at the root of this repository. `acs init` downloads the latest version of that file and writes it to `~/.acs/config.json`, so a fresh install always starts from the current list (pass `--offline` to use the copy bundled with the package instead).

| Source | Repository | Enabled |
| --- | --- | --- |
| anthropic-skills | [anthropics/skills](https://github.com/anthropics/skills) | yes |
| superpowers | [obra/superpowers](https://github.com/obra/superpowers) | yes |
| composio-awesome-claude-skills | [ComposioHQ/awesome-claude-skills](https://github.com/ComposioHQ/awesome-claude-skills) | yes |
| sickn33-agentic-awesome-skills | [sickn33/agentic-awesome-skills](https://github.com/sickn33/agentic-awesome-skills) | yes |
| alirezarezvani-claude-skills | [alirezarezvani/claude-skills](https://github.com/alirezarezvani/claude-skills) | yes |
| behisecc-awesome-claude-skills | [BehiSecc/awesome-claude-skills](https://github.com/BehiSecc/awesome-claude-skills) | yes |
| travisvn-awesome-claude-skills | [travisvn/awesome-claude-skills](https://github.com/travisvn/awesome-claude-skills) | yes |
| humanlayer-skills | [humanlayer/skills](https://github.com/humanlayer/skills) | yes |
| mattpocock-skills | [mattpocock/skills](https://github.com/mattpocock/skills) | yes |
| k-dense-scientific-agent-skills | [K-Dense-AI/scientific-agent-skills](https://github.com/K-Dense-AI/scientific-agent-skills) | yes |
| cloudflare-security-audit-skill | [cloudflare/security-audit-skill](https://github.com/cloudflare/security-audit-skill) | yes |
| ayghri-i-have-adhd | [ayghri/i-have-adhd](https://github.com/ayghri/i-have-adhd) | yes |

Know a good repository of skills that is missing? Open a pull request that adds it to `config.json`:

```
{ "name": "owner-repo", "repo": "https://github.com/owner/repo", "enabled": true }
```

`name` is the folder the repository is cloned into and the label used everywhere in the catalog, `repo` accepts https URLs, `owner/name` GitHub shorthand, ssh URLs, or local `file://` URLs. `trust` (0-100, default 50) says how much the copy from that repository should win when the same skill exists in more than one source.

## Installation

```
npm install -g ai-community-skills
```

Or run it without installing anything:

```
npx ai-community-skills init
```

The binary is available as `ai-community-skills` and as the short alias `acs`. Node.js 20 or newer and `git` on PATH are required. After installing, run `acs init` to write the default config to `~/.acs/config.json`, then `acs sync` to build the catalog.

## Commands

| Command | Description |
| --- | --- |
| `acs init` | Download the curated source list and write `~/.acs/config.json`. `--offline` uses the bundled copy. |
| `acs sync` | Clone or update every enabled source and rebuild the index. |
| `acs list` | List indexed skills with filters for category, risk, source, and findings. |
| `acs search <query>` | Search skills by name, description, category, and tags. |
| `acs info <skill>` | Full metadata, risk flags, findings, source reputation, and install state. |
| `acs validate [skill]` | Check frontmatter, referenced paths, and description quality. |
| `acs install <skill>` | Install a skill after a risk summary and a confirmation. |
| `acs uninstall <skill>` | Remove an installed skill. |
| `acs dedupe` | Remove duplicate copies of the same skill across sources. |
| `acs stats` | Counts by category, source, risk level, and finding. |
| `acs export-awesome-list` | Generate an awesome-list style markdown file from the catalog. |
| `acs ui` | Start the local web dashboard on port 8080. |

Every command that writes to disk has a `--dry-run` flag or asks for confirmation unless `--yes` is passed. Run `acs <command> --help` for the full list of flags.

## Usage

Build the catalog:

```
$ acs sync
Syncing anthropic-skills (https://github.com/anthropics/skills) ... updated, 19 skills indexed, 1 skipped
Syncing superpowers (https://github.com/obra/superpowers) ... unchanged, 14 skills kept
...
Index rebuilt with 3315 skills from 5 source(s).
```

A source whose repository did not change since the last sync keeps its index entries instead of being rescanned, so a routine sync takes a few seconds. The index is rebuilt anyway after upgrading acs, or on demand with `acs sync --force`.

Search and inspect:

```
$ acs search "frontend design"
$ acs info frontend-design
```

Install into Claude Code (personal scope, `~/.claude/skills/<name>`), into the current project, into Codex, or into Grok Build:

```
$ acs install frontend-design
$ acs install frontend-design --project
$ acs install frontend-design --target codex
$ acs install frontend-design --target grok
$ acs install frontend-design --target web
```

`--target web` produces a zip in `./acs-exports/` for manual upload to claude.ai. When a skill name exists in more than one source, add `--source <name>`. Installed copies are never updated automatically: `acs sync` warns when the upstream copy changed, and you decide whether to reinstall.

## Web dashboard

```
acs ui
```

Opens a local dashboard on <http://127.0.0.1:8080> with the same catalog: search and filters, skill pages with rendered SKILL.md and a file browser, every risk finding with a link to the exact line, favorites and groups that can be installed in one go and shared as JSON, source management with a trust level per repository, and duplicate cleanup. Every view has a shareable URL.

[Browse the catalog](https://github.com/xm1k3/ai-community-skills/blob/main/docs/assets/browse.jpg)

[Skill page](https://github.com/xm1k3/ai-community-skills/blob/main/docs/assets/skill.jpg)

[Sources](https://github.com/xm1k3/ai-community-skills/blob/main/docs/assets/sources.jpg)

## Risk analysis

Every skill is analyzed statically, nothing found in a skill is ever executed. Each entry records whether it ships scripts, references network calls, contains destructive operations and whether they are paired with a confirmation, uses Claude Code specific frontmatter, contains prompt injection patterns, or references secrets and credential files. The result is a `low`, `medium`, or `high` risk level plus the list of findings, each with file, line, and excerpt, so you can judge false positives yourself before installing.

Duplicates across sources are detected with a normalized content hash that ignores catalog metadata and whitespace, and the copy from the most trusted source is kept.

## Config

Your local `~/.acs/config.json` is yours to edit, from the file or from the Sources page of the dashboard:

```
{
  "sources": [
    { "name": "anthropic-skills", "repo": "https://github.com/anthropics/skills", "enabled": true, "trust": 100 },
    ...
  ],
  "dedupeAfterSync": true
}
```

All data lives under `~/.acs/` (config, index, install records, favorites and groups, cloned sources). Set `ACS_HOME` to use a different directory.

## Updates

Once a day (once an hour while `acs ui` is running) acs asks the npm registry for the latest published version. When a newer one exists, every command prints a short notice on stderr and the dashboard footer shows an upgrade button with the command to run:

```
npm install -g ai-community-skills@latest
```

The check never blocks a command for more than a moment, the result is cached in `~/.acs/update-check.json`, and nothing else is sent. Set `ACS_NO_UPDATE_CHECK=1` to turn it off.

## Disclaimer

Skills are community content pulled from third-party repositories. The risk analysis is heuristic and static: it will produce false positives and can miss real problems. Read a skill before installing it, especially anything rated high. The author is not responsible for what an installed skill does in your environment.

## License

ai-community-skills is distributed under the MIT License.
xm1k320
🟧 echo.github ⭐The released local catalog supports searching and installing community skills with static risk findings, source trust preferences, and explixm1k3——
🟧 hnSkill Poisioning turning AI agents into malware droppersgiuliomagnifico10
🟧 hnBashka – static analyzer for bash install scripts (for safety and convenience)neogoose11
🟧 hnShow HN: Bastionskill – scan an AI agent skill for malicious codeRinkia10
🟠 redditHow do you handle tool sprawl and untrusted scripts when building with Claude Code and custom agents?
ClaudeAI
_P_R_I_M_E14
🟠 redditI built an open-source skill that audits other agent skills before you install them
ClaudeAI
masiha9700

Interpretation history

Decision trace