This one’s a warning:
As co-work and agent platforms grow, we’re going to see marketplaces and repositories full of downloadable skills - pre-built automations you can drop into your setup and run immediately. Some of them will be genuinely great.
Some of them will be Trojan horses.
We’ve already watched this happen in the open-source software world over the past year. Malicious actors contributing “helpful” fixes to public repositories - fixes that also quietly exfiltrate data. It’s a proven attack vector.
The exact same thing is coming for AI skills. A skill is, at its core, a small piece of business process logic and software running on your machine. If it was built by someone you don’t know and can’t vet, you don’t actually know what it’s doing.
Claude Cowork does a good job of isolating skills into individual virtual machines, which limits the blast radius. But that only goes so far if the skill itself is designed to copy your data somewhere it shouldn’t go.
My rule: Only use skills from organizations or individuals you can actually verify. The same instinct you’d apply before running a random app on your work computer applies here.
The opportunity with co-work is real and exciting. But we have to bring the same security mindset we’d apply anywhere else.