When to Choose Each Option
Clear guidance based on your specific situation and needs.
Our Recommendation
Scanning agent skills before you install them is the clear baseline — the data is not subtle. With Snyk finding prompt injection in 36% of audited skills and 1,467 malicious payloads across the supply chain, and Mondoo reporting that more than one in four public skills carry vulnerabilities, treating every third-party skill as untrusted code is simply table stakes in 2026. A scanner like NVIDIA's open-source SkillSpector — which checks 64 vulnerability patterns across 16 categories before installation — catches the obvious supply-chain traps that an unvetted install walks straight into. But don't mistake a clean scan for safety: Trail of Bits has already bypassed a public registry's malicious-skill detector, so scanning is necessary, not sufficient. The approach Context Studios takes, and the one we'd recommend, is layered: scan every skill before install, run it under least-privilege sandboxing, review its provenance and requested permissions, and never let an agent install skills autonomously. Skipping the scan only makes sense for skills you wrote yourself or that come from a source you fully control. For anything pulled from a public registry, scan first, sandbox always, and trust nothing by default. One update since this page was first written, and it cuts at the layer beneath the scanner. On 30 July 2026 JFrog demonstrated that 54 of 55 CVEs published from a single GitHub account were AI-fabricated — six SQLite advisories rated as high as 9.8 Critical referenced functions that did not exist in the targeted version, cited line numbers past the end of the file, and claimed patches that a diff shows never happened. NVD flagged them critical and CISA's ADP concurred. The cause is structural: MITRE's submission form verifies no identity, and NIST's manual NVD analysis has been paused since February 2024. So the argument for scanning still holds, but the claim it supports is narrower than it looks — a scanner is only as trustworthy as the feed it reads, and that feed is now demonstrably contaminated. Scan, sandbox, least-privilege, and verify any finding that would trigger real work against the upstream project's own advisory page.
- Choose Scanned Agent Skills when...
- You install skills from public registries where you don't control the authors
- Your agents handle credentials, customer data or anything connected to real money
- You operate in a regulated or client environment that requires an audit trail
- You run multi-agent or autonomous workflows where one bad skill can spread fast
- Choose Unvetted Agent Skills when...
- The skill is one you wrote yourself or comes from a source you fully control
- You're prototyping in a throwaway sandbox with no secrets and no network access to anything sensitive
- You need a brand-new skill the moment it ships and accept the risk consciously
- You have other strong controls (strict sandboxing, no credential access) that contain a bad skill anyway