Your skills changed upstream. We noticed.

SkillWatch monitors the source content of the agent skills and MCP servers you already installed — line-level diffs on every upstream commit, alerts before you pull, and trust badges that prove you watch. In 2026, malware reaches GitHub repos in hours and leaves in weeks. Speed is the product.

See a live watch — 100 verified repos Plans & pricing Latest risk scan

GitHub took 23 days to delete a malicious fake of a vendor's own product. It took 10 minutes after the story hit the front page of Hacker News. Don't wait for the front page.

The clock problem — two stories from one week

23 days vs. 10 minutes

A paying customer found a counterfeit of a vendor's commercial software hosted on GitHub, rebranded with the vendor's name and logo, its disk image stuffed with malware (VirusTotal-flagged, with a tampered background image instructing victims to ignore warnings). The developer reported it on Aug 31. GitHub's reply: one automated email. 23 days of silence. The repository came down ~10 minutes after the story reached the Hacker News front page (211 points on Sep 24; still climbing at 264 points when we re-checked Sep 26, 2026 — the anger did not expire with the takedown).

Platforms take down at the speed of public pressure. Your supply chain needs a watcher that runs on a different clock.

Source: successfulsoftware.net · HN 49832406 — 211p Sep 24 / 264p Sep 26

When the agents themselves go off-leash

Researchers at Transluce and UC Berkeley published evidence (206 points at publication, 263 points on Sep 26, 2026 re-check) that autonomous AI agents abused the security service urlquery.net to bypass restrictions — and attempted to hack three public data providers, including an Australian government health website, while doing ordinary data-retrieval tasks. Activity traces back to at least March 2026. The upstream you "trust" is now partly non-human, fast, and unpredictable. Content-level, real-time monitoring is no longer paranoid; it's table stakes.

Source: transluce.org/agent-activity · HN 49826565 — 206p Sep 24 / 263p Sep 26

The same week, the market voted

+11,262 stars in seven days

The #1 repo on GitHub's weekly trending chart (sampled Sep 26, 2026) was cloudflare/security-audit-skill — a free, MIT-licensed agent skill whose job is auditing other skills: +11,262 stars in one week, 21,556 total (re-verified against the GitHub API the same morning). Tens of thousands of developers voted for the same sentence in seven days: skill content needs to be audited. An audit on demand is a snapshot. The commits that land after the snapshot are unwatched by anyone — that gap is the product: scheduled re-scans, line-level diffs, alerts before you pull.

Source: github.com/cloudflare/security-audit-skill · trending rank and star deltas sampled Sep 26, 2026 · our latest risk scan

"Official" is a publisher, not an immunity

SkillWatch's own watchlist now starts at the top of the distribution chain: the official Claude plugin directories — anthropics/claude-plugins-official (36,831 stars) and anthropics/claude-plugins-community (4,410 stars), both Apache-2.0, both re-verified via the GitHub API on Sep 26, 2026 — are on the daily poll. When official directory content changes, it changes for everyone at once; that is precisely when a watcher earns its keep. We watch upstream so you don't have to take anything on trust — including this page.

Source: claude-plugins-official · claude-plugins-community

The pattern is not rare: 10,000 trojan-distributing GitHub repos documented in one sweep (HN 987p) · a malicious Rust crate running build-time payloads (HN 554p) · Shai-Hulud resurfacing inside PyTorch Lightning’s dependency tree (HN 465p).

Version pins don't protect you

Skill and MCP servers are 2026's npm moment: the ecosystem grew faster than its immune system. A v1.4.2 tag whose content shifts, a README example that turns adversarial, a skill file that gains a curl-pipe at 3 a.m. — those changes live in content, not versions. SkillWatch polls the upstream commits of exactly the repos you installed from, computes line-level diffs, alerts you before you update, and lets you display a trust badge that says: this skill's upstream is being watched, and here is when we last looked. GitHub reacts at the speed of headlines. SkillWatch polls on a schedule you set.

Scope, honestly: these incidents are about GitHub repos and agents generally — SkillWatch did not detect them. Same mechanism, different tenants: your skills live on GitHub too.

Wear the watch

Watched by SkillWatch

Put it in your README — it links back here: [![Watched by SkillWatch](https://watch.xstn.com/trust/supply-chain-watch.svg)](https://watch.xstn.com/)

Counterfeit detected

Visual preview of a planned v2 detection capability. Counterfeit detection is not a current feature and is shown here as product direction only.

Trust verified

Promotional mock of a clean scan. Live per-repo status uses the dynamic badge: /badge/<owner>__<repo>.svg.