The first systematic study of SKILL.md authoring identified 44 lower-level components and found at least one violation of recommended practice in more than 99% of the 238 real-world files evaluated.
READ THE STUDY ↗Agent skills turn prose into operational behavior. OpsChainAI publishes enterprise skills for AI governance, secure data access, MCP control, RAG, executive review, and operational decision support—designed to be scoped, testable, evidence-bound, and owned.
A SKILL.md file can be created in minutes. That makes the format powerful—and makes quality, safety, and evidence the scarce part. A 2026 empirical study found that more than 99% of 238 sampled skills contained at least one “skill smell.” That does not mean 99% were worthless. It means almost none should be treated as production-ready merely because the Markdown looks plausible.
Research claims below are linked to the original papers and should be read in the context of their samples and experimental designs.
The first systematic study of SKILL.md authoring identified 44 lower-level components and found at least one violation of recommended practice in more than 99% of the 238 real-world files evaluated.
READ THE STUDY ↗SkillCorpus reported crawling roughly 821,000 skill artifacts and reducing them to 96,401 through a multi-stage curation pipeline organized around utility, robustness, and safety.
READ THE PREPRINT ↗A semantic supply-chain study found that description-only framing biased agents toward adversarial variants in paired trials and that some semantic evasion strategies bypassed registry governance checks.
READ THE SECURITY STUDY ↗It may sound authoritative while leaving the operating boundary undefined.
The instruction, operating boundary, evidence, and human decision point are all explicit.
The Agent Skills specification intentionally leaves the Markdown body flexible. OpsChainAI adds an enterprise assurance layer around that flexibility.
skill: rogue-mcp-tool-audit owner: Enterprise AI Governance version: 0.1.0 trigger: MCP inventory, tool approval, agent access review non_trigger: penetration testing or unauthorized system access evidence_required:server list, tool list, identities, permissions, logs critical_failure: unknown owner, broad credential, unlogged write capability decision: approve · remediate · quarantine · reject audit_output: capability map + finding register + action owner
The free starters demonstrate the standard. Professional packs add worksheets, evaluation suites, implementation patterns, and reusable evidence templates.
Review any SKILL.md before you install, publish, purchase, or approve it. Detect vague activation, hidden authority, missing evidence, unsafe tool use, weak failure handling, and absent evals.
Map what an AI system can read, what users can send, what the AI can touch, what it can decide, and what evidence remains after execution.
Inventory MCP servers and agent tools, identify unknown owners and identities, map permissions and egress, and classify each capability as approved, remediate, quarantine, or reject.
Determine whether retrieval preserves source authority, user entitlements, freshness, data lineage, DLP boundaries, citation requirements, and refusal behavior before a model sees content.
Classify proposed AI work by data sensitivity, action authority, external reliance, decision consequence, reversibility, human oversight, and evidence requirements.
Turn a technical proposal into an executive decision: business outcome, accountability, capability surface, control evidence, economics, model exit strategy, and named conditions for approval.
Design natural-language access to SQL, ERP, CRM, or operational systems without giving the model raw query authority, broad credentials, or uncontrolled write access.
Convert operational problems—shortages, production blockers, sales opportunity scoring, quality questions, and ERP reporting—into bounded AI workflows with owners and measurable outcomes.
A high-quality skill is still not a security boundary. OpsChainAI pairs executable operating methods with APEX controls that sit outside the model.
The library is designed as a credibility engine and a path to higher-value work—not a shelf of disposable prompts.
Inspectable methods that demonstrate the OpsChainAI standard and help teams improve internal practice immediately.
Complete methods for enterprise architects, AI leaders, CIOs, CISOs, and transformation teams.
Convert policies, workflows, institutional knowledge, and approval structures into a governed operating library.
OpsChainAI uses the open Agent Skills directory format and extends it with an enterprise assurance methodology.
OpsChainAI converts enterprise policies, expert judgment, operating procedures, and approval structures into tested Agent Skills—and connects them to governed capabilities through APEX.
paulh@npmit.com