Where we look for skills — and how they enter the test queue
We monitor 15 source surfaces across direct publishers, official collections, demand indexes, registries, and long-tail aggregators. 9 are covered by automated discovery or repository checks; the rest stay on a dated manual-review schedule.
Source map
Direct repositories and versioned registries can supply the artifact we inspect. Search tools, leaderboards, and directories only help us find it. Every aggregator result must resolve back to a canonical source before any code runs.
| Source | Check | Signal used | Trust boundary |
|---|---|---|---|
| Agent Skills specification spec | 30d manual review | format reference | standard Format compliance is not evidence of usefulness, maintenance, or safety. |
| skills.sh demand index | 1d automated | deduplicated installs, 24-hour trending installs | discovery_only Install telemetry measures demand, not successful use; skills.sh explicitly does not guarantee quality or safety. |
| GitHub Skill Search code search | 1d automated | repository stars | enhanced Code Search needs authentication, is rate-limited separately, and returns relevance rather than a quality ranking. |
| Anthropic skills official collection | 7d automated | skills.sh installs, repository stars | standard Official authorship narrows provenance risk but does not replace install, function, effect, or workflow testing. |
| OpenAI Skills Catalog official collection | 7d automated | skills.sh installs, repository stars | standard The catalog is first-party for Codex, not a complete view of community demand or cross-agent compatibility. |
| GitHub awesome-copilot official collection | 7d automated | repository stars, contributors | enhanced Collection inclusion is curation, not proof that each contributed skill works in our environment. |
| Claude plugin marketplaces marketplace protocol | 7d automated | repository stars, marketplace contributor activity | enhanced A plugin may bundle hooks, agents, MCP servers, or executables beyond a portable SKILL.md; components must be separated before comparison. |
| ClawHub registry | 1d automated | installs, downloads | quarantine OpenClaw-specific metadata and powerful execution patterns can be incompatible or high-risk elsewhere; every candidate stays quarantined until source, permissions, and scripts pass review. |
| VoltAgent awesome-agent-skills curated list | 14d automated | repository stars, contributor activity | discovery_only The collection warns that entries are curated but not audited; candidates must resolve to their original repositories. |
| Composio awesome-claude-skills curated list | 14d automated | repository stars, pull-request activity | discovery_only Some entries are links, some are copies, and some include adjacent plugin formats; provenance and duplication require manual resolution. |
| SkillsMP broad index | 14d manual review | GitHub stars shown by the index | discovery_only Very broad indexing maximizes recall but not precision; the service says it does not certify safety or quality. |
| SkillsMD Registry broad index | 30d manual review | registry installs, trending movement | discovery_only Registry counts and contributor totals are discovery hints until reconciled with the original source and another demand signal. |
| SkillMD broad index | 30d manual review | registry listing prominence | discovery_only Registry labels and compatibility claims need confirmation against the original package and our target agent. |
| mdskills.ai broad index | 30d manual review | marketplace listing | discovery_only Marketplace inclusion is not an independent functional test; compare only after resolving the canonical repository. |
| officialskills.sh curated list | 14d manual review | directory inclusion, linked repository stars | discovery_only Official-source curation is useful for provenance, but linked skills still require permission, compatibility, and outcome testing. |
Current priority queue
This snapshot contains 10 candidates found through at least one of
the sources above. P0 means “test next,” not “recommended.” MONITOR
means the package is already inside its published evidence window.
| Queue | Candidate | Fit | Demand | Freshness | Why next / what blocks it |
|---|---|---|---|---|---|
| P0 | frontend-designanthropics/skills | design fills-path-gap | 705.3K installs · 2.9K / 24h breakout | fresh · 2d license unresolved | First-party breakout candidate for the existing landing-page path; verify the skill-specific license before install. |
| P0 | remotion-best-practicesremotion-dev/skills | video published-dependency | 445.9K installs · 1.7K / 24h breakout | fresh · 2d license unresolved | The repository changed after our 2026-07-23 tested commit and feeds a published promo-video path. |
| P0 | general-videoheygen-com/hyperframes | video fills-path-gap | 133.5K installs · 2.9K / 24h breakout | fresh · 0d Apache-2.0 | High-demand, actively maintained video candidate; compare against the fixed Remotion brief after script and network review. |
| P1 | obsidian-vaultmattpocock/skills | obsidian fills-path-gap | 167.1K installs · 2.3K / 24h breakout | fresh · 3d MIT | Breakout community candidate for a same-brief comparison with the already tested kepano pack. |
| P2 | vercel-react-best-practicesvercel-labs/agent-skills | development coverage-expansion | 579.9K installs · 1.7K / 24h breakout | fresh · 2d license unresolved | First-party breakout candidate, but lower immediate fit than the three public path gaps. |
| P2 | ai-video-generation101-skills/skills | video fills-path-gap | 383.5K installs · 22.4K / 24h breakout | fresh · 16d license unresolved | Exceptional install velocity but much lower repository adoption and unresolved license; enhanced provenance and duplicate review comes first. |
| P2 | seo-auditcoreyhaines31/marketingskills | marketing coverage-expansion | 170.8K installs breakout | fresh · 3d MIT | High-demand marketing candidate with active maintenance; needs a fixed site and measurable audit-recall verifier. |
| P2 | webapp-testinganthropics/skills | testing coverage-expansion | 121.7K installs breakout | fresh · 2d license unresolved | First-party breakout candidate that can add a missing testing goal family; verify declared tools and dependencies first. |
| P2 | landing-page-design101-skills/skills | design fills-path-gap | 24.6K installs · 1.5K / 24h strong | fresh · 16d license unresolved | Strong demand signal, but the same source-level provenance, license, and duplication checks block hands-on execution. |
| MONITOR | obsidian-markdownkepano/obsidian-skills | obsidian published-dependency | 62.7K installs strong | active · 48d MIT | Already install-verified in the five-skill pack; monitor until the 30-day deadline or an event trigger fires. |
Update and retest frequency
Source checks and hands-on retests are separate. Fast-moving demand indexes can be scanned daily without reinstalling anything. A full retest repeats clean install, activation, function, failure, and artifact checks on the pinned version.
| Priority | Metadata | Full retest | Rule |
|---|---|---|---|
| P0 | 1d | 14d | Published-path dependency changed, or a first-party breakout candidate fills a current path gap. |
| P1 | 7d | 30d | Strong or breakout demand with clear provenance, recent maintenance, and direct goal coverage. |
| P2 | 14d | 60d | Proven demand but enhanced provenance, duplication, compatibility, or security review is still required. |
| P3 | 30d | 90d | Emerging or low-signal long tail; test only for a documented coverage gap or user request. |
Some changes bypass the calendar. A security warning, archive or rename, license change,
installer or permission change, silent content-hash change, or a changed dependency in a published
Path creates an immediate review. Published-path changes become P0 and are due within
seven days; a high or critical security result is quarantined the same day.
What every comparison must include
Install totals and stars remain separate dated fields. We do not add unlike counters into a single “quality score,” because that precision would be fictional.
| Comparison dimension | Evidence required |
|---|---|
| Goal fit | Same fixed brief and final artifact contract for every candidate. |
| Provenance | Canonical source, publisher class, license, pinned commit, and duplicate check. |
| Demand | Dated installs plus repository stars; never add unlike counters into one score. |
| Freshness | Last meaningful source change, test date, and whether upstream changed after the tested commit. |
| Maintenance | Archived state, releases or meaningful commits, and issue response evidence when relevant. |
| Security | Static review, requested tools and secrets, bundled scripts, network behavior, and third-party audits. |
| Install | Clean-environment command, measured duration, payload, dependency failures, and uninstall path. |
| Activation | Positive triggers, negative controls, false activation, and competing-skill behavior. |
| Function | Deterministic minimum task, expected output, failure injection, and repeat run. |
| Effect | Same input with and without the skill, artifact-level verifier, and human review where needed. |
| Portability | Declared agents, OS and runtime requirements, path assumptions, and cross-agent limits. |
| Update cost | Change frequency, migration surface, lock or pin support, and next retest deadline. |
Known blind spots are part of the report
- GitHub search can miss a useful skill whose name and description are vague.
- CLI telemetry shows installs, not whether the user completed a task or kept the skill.
- Repository activity can be documentation churn rather than meaningful skill maintenance.
- Registry security badges can lag the current content hash and never replace our script and permission review.
- Private, paid, enterprise, and non-indexed skills remain invisible until a user supplies an inspectable source.
- Cross-agent compatibility is a claim until the same fixed brief passes on that agent.