AI Coding Tools Hit Their 'npm Moment' — and npm's Security Problems Came Free

AI Coding Tools Hit Their 'npm Moment' — and npm's Security Problems Came Free

Over the past six months, the hottest track in AI coding has been agents, long context, and MCP protocols — everyone competing on "whose model is stronger" and "whose context is longer." But Vercel made a different choice.

In January, Vercel founder Guillermo Rauch dropped a CLI tool on X: npx skills add. You cannot call it a model upgrade or an architecture breakthrough — it does something simple: one command installs a capability pack into your AI coding assistant. Five months later, the vercel-labs/skills open-source repository has 24,000 GitHub stars, and the top skill package find-skills on skills.sh has hit 2.3 million installs. Supported tools exceed 68: Claude Code, Cursor, Codex, Gemini CLI… nearly every mainstream AI coding assistant is in its install list.

This is not a feature update. It is a structural migration in the AI coding tool layer — from "prompt engineering" to "capability engineering." But history also tells us that every "npm-ization" wave ships convenience and security risks in the same package.

What It Actually Does: One Command, One Set of House Rules

The most visible part: npx skills add vercel-labs/agent-skills, hit Enter. Seconds later, your Claude Code has a set of React and Next.js engineering conventions plus a design guideline. Next time it writes code, it follows those rules automatically. Each "skill" is essentially a folder. The core is a SKILL.md with a YAML header specifying two things: what this skill is and when to use it. The folder can also hold reference docs, templates, and a dedicated scripts/ directory containing directly executable scripts.

It solves a very practical pain point. LLMs understand general programming languages and frameworks, but they do not know your project's house rules: your code style, naming conventions, historical pitfalls. Previously you had to re-explain these at every new conversation. Now you package them as a skill, install once, and they persist. Post-install management mirrors npm: list to see what's installed, update for one-click updates, remove to delete. The underlying spec is shared — what you install for Claude Code runs identically on Cursor. If even installing feels like too much, there is a lighter path: npx skills use temporarily pulls the skill, pipes it to Claude, and leaves nothing behind locally. It sounds exactly like npm — except this time you are installing not code libraries but "capabilities."

Not a Feature — an Ecosystem Play

Many will mistake this for an Anthropic or Cursor feature. It comes from Vercel — a company known for Next.js and for locking down the front-end ecosystem entrance through "developer experience." Vercel understands something about platform dynamics that pure model companies do not: the model layer commoditizes, but the capability layer — the accumulated conventions, templates, and scripts that make AI outputs match your team's standards — is where loyalty lives. By making skills cross-tool compatible (Claude Code, Cursor, Codex, Gemini CLI all supported), Vercel is positioning itself as the package registry for the AI coding era, regardless of which model or editor wins. That is the npm playbook exactly: become the default distribution channel, and you own the ecosystem regardless of upstream churn.

The 2.3 million installs on find-skills — a meta-skill that helps users discover other skills — signal that the discovery layer is already active. Developers are not just installing pre-packaged skills; they are searching for capabilities they did not know existed. This is the moment a package registry crosses from "convenience" to "dependency": when the first thing you do after setting up a new AI tool is run npx skills add, the registry has become infrastructure.

The npm Playbook's Shadow: Security Is Already Here

npm's history offers a preview of what is coming. Package hijacking, typosquatting, dependency-chain attacks, malicious code in popular packages — every one of these will have an AI-skills equivalent, potentially with higher stakes because skills contain not just code but behavioral instructions that shape how the AI operates. A malicious skill that subtly changes how your AI agent handles authentication, or that injects biased assumptions into code generation, would be harder to detect than a traditional npm vulnerability because the "payload" is not executable code but contextual influence.

The Vercel skills repository already requires authentication for publishing, and the SKILL.md format's declarative nature (Markdown plus YAML) makes it more auditable than compiled JavaScript. But auditability is not the same as auditing — someone has to actually read the skill's instructions before installing, and most developers will not. The industry will need skill-scanning tools, reputation systems, and possibly signed skills — the same infrastructure that npm grew after its first wave of security incidents.

What To Do

If you are a developer: start packaging your team's coding conventions as skills. The ROI is immediate — every new conversation, every new team member, every new project inherits your standards automatically. Audit third-party skills before installing: read the SKILL.md, check the scripts directory, and verify the source. If you are an AI tool vendor: the skills format is cross-tool, which means your users can leave. The defense is not blocking the format but building the best skill ecosystem for your tool — curation, quality signals, and seamless integration. If you are an enterprise: skills are a vector for both productivity and risk. Establish an internal skill registry, vet third-party skills before deployment, and treat skill management as you would dependency management — with the same rigor and the same security review process.

Scroll to Top