State of agent markdown, September 2026
We looked at 69,119 instruction files for AI agents (SKILL.md, AGENTS.md, CLAUDE.md, DESIGN.md, llms.txt and Cursor rules) from 2,887 public GitHub repositories. This report answers four questions: how often they change once we have collected them, whether copies of popular skills keep up with the original, how many follow the Agent Skills format, and what an automatic security check finds in them.
Key findings
- In the registry's corpus, roughly one in five agent markdown files changed within two weeks of being indexed. Of 47,724 files watched for at least 14 days, at least 9,487 (19.9%) received a new upstream commit within 14 days and at least 6,745 (14.1%) within 7. Without the ten most active repositories of each kind, the 14 day share is at least 17.8%.
- In the corpus, llms.txt files changed most often: at least 41.2% (106 of 257) changed within 14 days, followed by AGENTS.md at 27.8%, CLAUDE.md at 23.2%, SKILL.md at 19.4%, Cursor rules at 12.2%, DESIGN.md at 5.4%, each a lower bound.
- In the registry, copies of Anthropic's skills can fall behind their source. For 5 skills from the anthropics/skills repository (skill-creator, frontend-design, docx, pptx and xlsx), chosen because they change often, 75 files in other repositories are byte-for-byte copies of a recorded upstream version, and 47 of them (62.7%) match an older version rather than the current one.
- About one in ten SKILL.md files in the registry breaks the Agent Skills specification's frontmatter rules. Of 60,844 SKILL.md files inside a skill directory, 54,836 (90.1%) conform; the most common failure is a name that does not match its directory (3,858 files, 6.3%).
- The audit flags 194 of 69,119 files (0.3%) on at least one critical check. The checks are deliberately broad, so emoji joiners, stray zero-width spaces, Persian text, the example access key from Amazon's documentation, code that reads environment variables, security guidance that quotes an attack and security test fixtures trip them too; a flag means read this file, not that it is malicious.
- In the registry, 458 files contain a curl or wget command piped straight into a shell, 395 of them SKILL.md files.
- In the registry, 5.7% of SKILL.md files (3,487 of 61,170, across 254 repositories) are byte-identical to a file in another repository. DESIGN.md reads 53.3%, but 540 of its 555 copies sit in four repositories that carry the same template set.
How often agent markdown changes
An agent that loads a skill or an AGENTS.md by reference reads whatever the file says today. The registry records a new version whenever a file's bytes change upstream to content it has not held for that file before (a revert to an earlier version is not counted again), so it can count how many files changed after it first indexed them. Every file below was watched for at least 14 days (between 14 and 21.8 days on the day the data was frozen), so each had a full 14 days to change upstream. Not every repository was re-checked inside that window, so every figure in this section is a lower bound. Changes also cluster in active repositories, so the last column repeats each share without the ten repositories of that kind with the most changes.
| Kind | Watched 14+ days | Changed within 7 days | Changed within 14 days | Share within 14 days | Share without its 10 most active repositories |
|---|---|---|---|---|---|
| SKILL.md | 42,581 | 5,864 | 8,272 | 19.4% | 17.5% |
| AGENTS.md | 2,623 | 512 | 730 | 27.8% | 24.8% |
| CLAUDE.md | 1,333 | 240 | 309 | 23.2% | 21.0% |
| DESIGN.md | 634 | 27 | 34 | 5.4% | 3.9% |
| Cursor rules | 296 | 22 | 36 | 12.2% | 2.5% |
| llms.txt | 257 | 80 | 106 | 41.2% | 36.2% |
| All kinds | 47,724 | 6,745 | 9,487 | 19.9% | 17.8% |
To keep an agent on the version you reviewed, pin by content hash rather than by path. mdr add owner/repo/name records the file's SHA-256 in mdr.lock, mdr outdated reports every pinned artifact whose main file (SKILL.md for a skill) changed upstream, and mdr diff shows that change before you take it. See how to pin an agent skill to an exact version.
Copies of Anthropic's skills can fall behind
Many repositories carry a copy of a skill from anthropics/skills in their own tree. A copy does not update when the source does. For the 5 skills below, the registry holds at least three upstream versions, so it can tell a copy of the current version from a copy of an older one by comparing bytes exactly. They were chosen for that reason, which favors skills that change often.
| Skill | Upstream versions recorded | Copies of the current version | Copies of an older version | Share on an older version |
|---|---|---|---|---|
| skill-creator | 4 | 14 | 8 | 36.4% |
| frontend-design | 4 | 3 | 12 | 80.0% |
| docx | 4 | 3 | 10 | 76.9% |
| pptx | 3 | 3 | 8 | 72.7% |
| xlsx | 3 | 5 | 9 | 64.3% |
| All 5 | 28 | 47 | 62.7% |
Only byte-exact matches are counted. 191 of the 266 files that share one of these names match no recorded upstream version and are left out, because each may be an edited copy, an unrelated skill that happens to share the name, or a copy of a version older than the history the registry holds (it recorded up to the five most recent commits of each file when it first crawled it, from September 5, 2026). So the share on an older version is a count of copies that are provably behind, not an estimate.
Conformance to the Agent Skills specification
The Agent Skills specification requires YAML frontmatter with a name of 1 to 64 lowercase letters, digits and hyphens, with no leading, trailing or doubled hyphen, equal to the skill's directory name, and a non-empty description of at most 1,024 characters. The counts below cover the 60,844 SKILL.md files that sit inside a directory; a file can fail more than one rule.
| Rule | Files failing | Share |
|---|---|---|
| No name | 1,244 | 2.0% |
| Name has characters or hyphens the specification does not allow, or is over 64 characters | 1,327 | 2.2% |
| Name does not match its directory | 3,858 | 6.3% |
| No description | 979 | 1.6% |
| Description over 1,024 characters | 601 | 1.0% |
| Conforms to every rule above | 54,836 | 90.1% |
What the security audit finds
Every version is graded by the same deterministic checks, with no model involved: A passes everything, B fails one advisory check, C fails two or more, and F fails a critical check. The audit labels and never blocks; the grade is on every file's page. Figures are for the latest version of each file.
| Kind | Files | A | B | C | F | Share F |
|---|---|---|---|---|---|---|
| SKILL.md | 61,170 | 57,008 | 2,946 | 1,042 | 174 | 0.3% |
| AGENTS.md | 3,901 | 3,570 | 316 | 6 | 9 | 0.2% |
| CLAUDE.md | 2,081 | 1,387 | 682 | 6 | 6 | 0.3% |
| DESIGN.md | 1,042 | 1,025 | 15 | 1 | 1 | 0.1% |
| Cursor rules | 510 | 460 | 48 | 0 | 2 | 0.4% |
| llms.txt | 415 | 351 | 54 | 8 | 2 | 0.5% |
Critical checks. Any one of these makes a file grade F. Files are counted once per check, so the rows can add up to more than the number of F files. The checks are pattern matches written to catch hidden instructions, and they are deliberately broad: the zero-width check also fires on the joiners inside some emoji, on stray zero-width spaces pasted into text, and on Persian spelling; the credential-shape check fires most often on AKIAIOSFODNN7EXAMPLE, the example key in Amazon's own documentation; the credential-sending check also fires on code such as process.env, on advice about keeping .env files out of git, and on security guidance that quotes the attack it warns about; and security projects keep deliberately malicious test fixtures. A grade F means a person should read the file, not that it is malicious.
| Critical check | Files |
|---|---|
| Zero-width or bidirectional control characters | 91 |
| An instruction to send local credentials somewhere | 31 |
| Text hidden with inline styles | 30 |
| A link to an exfiltration or paste host | 22 |
| A credential-shaped string | 18 |
| An instruction hidden inside an HTML comment | 8 |
Advisory checks. Each lowers a grade from A without failing the file. The grade also counts hygiene checks not listed here: a size between 200 bytes and 200 KB, and for SKILL.md files the frontmatter, name and description. Some matches are legitimate (an install guide that pipes curl into a shell is still one), which is why these are advisory.
| Advisory check | Files | SKILL.md files |
|---|---|---|
| curl or wget piped into a shell | 458 | 395 |
| An instruction to read or print local credentials | 332 | 293 |
| Prompt-injection phrasing | 247 | 236 |
| A recursive delete of root, home or parent | 62 | 54 |
| A script tag | 823 | 718 |
| A link to a raw IP address | 691 | 611 |
| A base64 blob over 200 characters | 35 | 34 |
Browse the files that fail a critical check at grade F.
The most-copied files
A file counts as copied when a byte-identical file sits in another repository. Files under 200 bytes are left out: many are git symlinks whose whole content is a path such as AGENTS.md. Copies are not spread evenly, so read each share with the number of repositories that hold it.
| Kind | Copies | Share of files | Repositories holding copies | Copies in the top four repositories |
|---|---|---|---|---|
| SKILL.md | 3,487 | 5.7% | 254 | 602 |
| AGENTS.md | 403 | 10.3% | 85 | 188 |
| CLAUDE.md | 40 | 1.9% | 24 | 20 |
| DESIGN.md | 555 | 53.3% | 17 | 540 |
| Cursor rules | 14 | 2.7% | 4 | 14 |
| llms.txt | 16 | 3.9% | 10 | 10 |
The ten most-copied files. "Repositories" counts where the same bytes appear; "identical files" counts every file with those bytes, including the original and twins inside one repository. Ties are broken by the registry's file id. The link goes to the first copy the registry saw.
| File | Kind | Repositories | Identical files |
|---|---|---|---|
| AGENTS.md@apps/web | AGENTS.md | 15 | 18 |
| skill-creator | SKILL.md | 15 | 15 |
| doc-coauthoring | SKILL.md | 12 | 12 |
| AGENTS.md@benchmarks/runs/superpowers | AGENTS.md | 10 | 13 |
| internal-comms | SKILL.md | 10 | 10 |
| theme-factory | SKILL.md | 10 | 10 |
| codebase-design | SKILL.md | 9 | 10 |
| brand-guidelines | SKILL.md | 9 | 9 |
| SKILL.md | 9 | 9 | |
| algorithmic-art | SKILL.md | 9 | 9 |
Method
- Corpus. 69,119 live files (214,457 recorded versions of those files) from 2,887 public GitHub repositories and 2,607 owners, crawled directly from GitHub since September 5, 2026. Repositories are found by GitHub topic searches (agent-skills, claude-skills, claude-code-skills, skill-md, agentskills and claude-code-plugin, each with a floor of two or three stars) and a search for SKILL.md in READMEs of repositories with ten or more stars, excluding forks and archived repositories; each search takes its 100 most recently updated matches once a day, so the corpus leans toward repositories that were active when found. A seed list adds more, partly hand-picked and partly from a search for marketing tools. At most 200 agent files are indexed per repository. So the AGENTS.md, CLAUDE.md, DESIGN.md and llms.txt files here are the ones that live in repositories found that way. This is the registry's corpus, not a random sample of GitHub, and every figure describes it.
- A change. A new upstream version whose commit date is later than the moment the registry first indexed the file. The first crawl also records up to five earlier commits; those are history, not change, and are excluded by the date. 1,696 files first indexed early enough to count were later deleted or moved upstream; that is also a change, but they are left out of the figures above.
- The window. Only files first indexed at least 14 days before the data was frozen count toward the change figures, so every counted file had a full 14 days to change. Some repositories are not re-crawled every day, so a change can be recorded late and the 14 day figures are lower bounds. This first edition covers a short window; later editions will extend it.
- A copy. A file is a copy when its SHA-256 content hash equals that of a file in another repository and it is at least 200 bytes long. Twins inside one repository (often mirror folders of the same plugin) and files under 200 bytes (often git symlinks) do not count. The vendored-skill figures use a different test: equal to a recorded version of the upstream skill itself.
- The audit. 43,512 of the latest versions were graded by audit version 3 and 25,607 by version 4. The only difference is that version 4 recognizes more forms of private-key header, so the credential-shaped string count is a lower bound for the version 3 files; every other check is identical.
- Reproduce it. Every file's versions, hashes and audit are public at its page and through the registry API; the JSON download is the exact data this page renders, and the CSV carries its figures one per row.
You may quote and republish these figures with a link to this page.
Sources
Read next
- How to pin an agent skill to an exact version
- Are agent skills safe? What to check before you install one
- SKILL.md format: the required frontmatter fields
- Every SKILL.md skill in the registry
Try it
npx modelranch add anthropics/skills/pdf