The new '/learn' skill installers and public skill directories are going viral, but users are actively questioning whether copied public skills are safe: why it is not safe to use
Public AI skill installers are spreading fast, but users are openly questioning whether copied marketplace skills are safe to trust as-is.
What happened
Public directories for AI "skills" are spreading quickly, especially among Claude users looking for easy ways to add new abilities. In a recent Reddit thread, people asked where to find public skills, and commenters pointed to directories such as skills.sh. In the same discussion, some users warned that copying public skills can leave behind "prompt injection ghosts," meaning hidden instructions or behaviors that may affect how an AI agent responds later.
A Product Hunt page for Agent Skills says its `/learn` installer can install other skills, supports Claude Cowork through a zip download, and lets agents report back after use. That kind of one-click setup may make these tools more appealing to non-technical users. The page also says listings are ranked partly by a security score, but version pinning is not yet implemented. Version pinning means locking to one known version so it cannot silently change later. The page says it uses content-SHA tracking instead, which is a file fingerprint.
What it means for you
If you use an AI agent for work or personal tasks, the main issue is trust. Public skill marketplaces may be convenient, but the current public discussion is focused on whether copied skills are safe enough to use without checking them.
What to do instead
Use caution with one-click installs from public directories. Prefer skills from sources you recognize, read the listing carefully, and avoid giving a new skill access to sensitive files or accounts right away. If possible, test a skill in a low-risk workspace first. Keep notes on what you installed so you can remove it later if needed. AgentPod lists only reviewed, tested skills, which can be a safer starting point, but you should still check what any skill is meant to do before using it.
Sources:
- https://www.reddit.com/r/ClaudeAI/comments/1vqv6pp/how_are_you_guys_discovering_new_claude_skills/
- https://www.producthunt.com/products/agent-skills-3
Source: https://www.reddit.com/r/ClaudeAI/comments/1vqv6pp/how_are_you_guys_discovering_new_claude_skills/
We report what our security review found at the time we checked, with the goal of keeping people safe. Projects change; if a maintainer has since fixed this, we are glad to recheck it. Email hello@agentpod.com.