Agent skills are having their npm moment — and not the good part. The extensions you plug into Claude Code or Codex run with implicit trust and almost no vetting. NVIDIA just put a number on it.
I built a Claude skill that creates ghost personas to review your code before production.
6 lines of code. "Looks fine, ship it."
Then 3 ghosts showed up:
😈 Hit Back twice — 630 TL cart became 322 TL
🏢 Paid in EUR — discount never applied
🐵 DB dropped mid-loop — half the data corrupted
3 bugs. 0 tests written. Before the PR even opened.
Open source → https://t.co/ZecOZGsacj
Cogu AI projesi modelden degil, sirketten dolayi batiyor.
Demo etkileyici. PoC hizli cikiyor. Uretimde her sey patliyor.
Sorun model degil. Yonetim modeli yok.
Asil rekabet "kim daha hizli AI kullaniyor" degil.
Asil rekabet su:
Kim AI ile gercek is sonucunu daha guvenilir, daha olculebilir, daha sorumlu sekilde uretebiliyor.
AI bir cift yuzlu katana. Yanlis elde once kullananiyla keser. 5/6