Anthropic Claude Agent Skills: The 2026 Leaderboard and Governance Risks
A community-built skill overtakes Anthropic’s own frontend-design as the most-installed Claude Agent Skill, while security audits reveal prompt injection in 36% of tested skills and raw install counts distort the market.
On 5 August 2026, a tracked ranking based on live skills.sh install data showed that a community-built skill called grill-me, created by developer educator Matt Pocock, had overtaken Anthropic’s own frontend-design as the most-installed Claude Agent Skill. The margin was narrow but decisive: 756,300 installs against 742,300, a swing of more than 150,000 installs in four weeks.
The shift matters because Claude Agent Skills are not just prompts. They are reusable, file-based capability packages — a SKILL.md file with instructions, tool references, and output constraints — that an AI agent loads only when a task matches. That design keeps token overhead low while turning ad hoc prompting into versionable, auditable workflow modules. For executives and engineering leaders, the ranking is a snapshot of a new supply-chain surface that is growing faster than most governance frameworks can track.
Skills shift AI agents from one-off prompting to auditable, versionable, cross-platform workflow modules — the difference between an AI assistant and a production-grade agent, and a new supply-chain security surface executives must govern.
The top ten, by the numbers
The most rigorous tracked ranking, published by O-mega on 5 August 2026 using live skills.sh install data, shows how quickly the leaderboard shifts. The top ten includes:
- grill-me (Matt Pocock) — 756.3K installs
- frontend-design (Anthropic) — 742.3K installs
- grill-with-docs — 641.9K installs
- agent-browser — 629.0K installs
- improve-codebase-architecture — 617.5K installs
- vercel-react-best-practices — 606.7K installs
- tdd — 595.4K installs
- web-design-guidelines — 516.5K installs
- Superpowers — 266.8K GitHub stars
- find-skills — 2.8M raw installs, discounted as a “bundler”
That last entry is a cautionary note: raw install counts can be distorted by bundler skills that pull in other packages. Even so, the broader registry grew from roughly 670,000 to 1,131,746 skills in the same four-week window, and rankings have a half-life of about four weeks.
From markdown folders to cross-platform standard
Anthropic launched Claude Agent Skills in October 2025 and published the specification as an open standard at agentskills.io on 18 December 2025. The format is deliberately simple: a folder containing a SKILL.md file with instructions and constraints. That simplicity is the point. The same skill now runs across Claude Code, OpenAI Codex, Cursor, Gemini CLI, GitHub Copilot, and roughly 40 compatible products.
The infrastructure around this format has grown quickly. Vercel launched skills.sh in January 2026, led by CEO Guillermo Rauch and creator Andrew Qu, and partnered with Gen, Socket, and Snyk for security audits. Anthropic’s official directory includes enterprise partners such as Atlassian, Canva, Cloudflare, Figma, Notion, Sentry, Stripe, and Zapier. Matt Pocock’s mattpocock/skills repository holds 251,000 GitHub stars and accounts for five of the top nine skills.
Performance gains and security risks
The performance case for curated skills is measurable. According to the tracked data, curated skills raise agent pass rates by an average of 16.2 percentage points. Yet the average public skill scores just 6.2 out of 12 on quality. That gap helps explain why only 17% of executives report full AI-agent adoption company-wide, according to Nimbleway.
Security is the sharper concern. A security audit of 22,511 skills found 140,963 issues. Snyk detected prompt injection in 36% of tested skills. Because the open format is essentially “markdown in folders,” unaudited and potentially malicious skills are trivial to ship. For enterprises, that makes skill selection a governance problem, not just a developer convenience.
Some skills also deliver efficiency gains. The Caveman skill cuts token usage by up to 65%. Meanwhile, ByteDance’s Lark enterprise skills entered the top 10 from nowhere, while Microsoft Foundry sits at #36 in raw installs — a sign that enterprise adoption is uneven and that raw counts do not always reflect production readiness.
What leaders should watch next
The rise of Claude Agent Skills marks a shift from one-off prompting to auditable, versionable, cross-platform workflow modules. But the ecosystem’s volatility is real. Rankings have a half-life of roughly four weeks, and bundler skills such as find-skills distort raw install counts. The open standard’s simplicity is both its strength and its vulnerability.
For executives, the immediate priority is supply-chain governance: knowing which skills are running inside agent workflows, who maintains them, and how they are audited. The fact that a single developer’s repository can hold five of the top nine skills — and that a new enterprise entrant can appear from nowhere — shows how fluid the market remains. As the registry crosses 1.1 million skills, the winners will not be the teams that adopt the most skills, but those that can trust the ones they run.
Sources
- Top 10 Anthropic Claude Agent Skills for 2026
- Top 10 AI Agent Skills in 2026: The Tracked Ranking | Articles | o-mega
- 10 Best AI Claude Skills to Supercharge Your Workflow (2026)
- Best Claude Code Skills to Try in 2026
- Top 10 AI Agent Skills for Claude Code in 2026 - Zima Store Online
Written by an AI editorial process from the sources above. Errors may occur.
Newsletter
Get the AI news that matters
One short brief with the day's most important AI stories — written for professionals.
We send a confirmation link. No spam. Unsubscribe anytime.
Read next
LLM Benchmarks in 2026: The 7 Evaluations That Matter
As MMLU saturates, model selection now depends on harder, contamination-resistant evals—from GPQA to SWE-bench Pro. Here are the seven benchmarks and evaluation strategies that define frontier AI in 2026.
6 Sep 2026
AI Video Generation in 2026: No Single Model Wins Every Task
ByteDance’s Seedance 2.0 leads text-to-video, Google’s Gemini Omni Flash tops image-to-video, and Alibaba’s Happy Horse 1.0 wins video editing, showing task-specific strengths and cost implications.
6 Sep 2026
Vercel vs Cloudflare AI Gateways: Production Trade-offs Compared
A deep dive into cost, reliability, and security differences between Vercel and Cloudflare’s AI Gateways for scaling LLM workloads.
2 Aug 2026