A Guide to Agent Skills
A working model for where agent skills actually create risk — and six practices for folding them into the governance you already run.
Skills promise something genuinely useful: turn a good agentic workflow into a reusable one, instead of re-deriving the same approach every time and hoping the agent gets it right. That’s exactly why they’re spreading fast across enterprises — and exactly why most security and governance conversations about them stop at the wrong layer, treating skills as a supply-chain problem when the real exposure runs through the same loop every agent already operates on.
This guide starts by building that loop out properly. The diagram below is the shared model the rest of the guide reasons from: every agentic task runs through interpret, plan, act, and feedback, riding on the tool environment underneath it. It’s this loop, not the skill file itself, that determines where risk actually lands.
From there, the guide walks through four documented risks a static review genuinely can’t catch, a stage-by-stage example of where a skill’s risk lands in a real security-operations workflow, and the specific mechanism that let a real malicious skill run code before a model ever reasoned about it.
It also makes the business case, not just the risk case. Skills can be dramatically cheaper than the alternative architecture for the same task — sometimes by two orders of magnitude in standing token cost.
Included:
- A shared model for how agentic risk forms, and exactly where a skill’s risk lands inside it
- Four documented risks that a pre-execution review of the skill artifact cannot catch — and why each one specifically evades review
- A precise breakdown of what a security check can and cannot see, for a skill versus an MCP call
- Six practices for bringing skills into the governance model your team already runs — from visibility through to using skills to lower your own risk