A new kind of AI marketplace just hit a milestone that took every other software platform in history years longer to reach. Skills.sh, a public library of instructions that teach AI agents how to do specific jobs, grew to one million listings and close to 280 million installs in just seven months. GitHub took twenty seven months to reach one million code repositories. Apple's App Store took just over five years to reach one million apps. Npm, the library most computer programs pull code from, took more than nine years.
A skill is simple in concept. An AI agent like Claude can already write, plan, and browse the web, but it has no idea how your specific company writes a contract, approves a refund, or formats a client report. A skill is a short file, often just plain instructions, that fills in that missing knowledge. Anthropic launched the feature in October last year, and in December opened it as a shared standard so any AI platform could use the same format. Companies people already use, including Atlassian, Figma, Canva, Stripe, Notion, and Zapier, signed on early to publish their own skills.
What people publish and what people actually use are two different stories. Most published skills are technical, aimed at software developers, because that is where the idea started. But installs tell a different story: expense reports, writing help, and cloud setup skills get installed far more often for every listing available than coding skills do. That gap is a signal, not noise. Non-technical teams want agents that help with everyday office work, but there simply are not as many well-made skills for that work yet compared to coding. Whoever builds the popular expense report skill, or the popular client onboarding skill, has an audience waiting.
The uncomfortable part of this story is security. Independent researchers at Snyk scanned nearly four thousand published skills and found that more than a third had some kind of security weakness, and a small number were outright malicious, built to steal passwords or plant hidden backdoors. Several of the most downloaded skills in similar registries turned out to be malware. A skill file looks like a harmless instruction sheet, but because an AI agent follows it literally, a skill can quietly tell the agent to send your data somewhere it should not go, and there is no obvious warning sign for someone who is not checking the code.
This mirrors exactly what happened to open source code libraries over the past decade, where popular but unverified packages became a favorite target for attackers, including a wave of compromised packages discovered as recently as this past September. The lesson for any business letting staff install AI skills is the same one security teams learned the hard way with code: install count is not a safety rating, and a company-wide policy on which skills are approved is worth setting up before your team downloads dozens of them on their own.
The more interesting shift is where the real value is heading. Skills that teach an agent knowledge everyone already has will become common and cheap. The skills worth paying for, or building in house, will be the ones that capture what only your company knows: exactly when a refund gets approved, exactly what a finished report should look like at your firm. That is not a technology problem anymore. It is a documentation problem, and the businesses that write their own playbooks down first will get more out of their AI agents than the ones waiting for someone else to sell them a generic one.