INDEX / MARKETPLACE
AI Agent Skills Marketplace (skills.sh alternative with security auditing)
A curated, security-audited marketplace for installable AI agent skills and capabilities, solving the trust and discovery problem for the growing ecosystem of agent orchestration platforms.
▶ WATCH THE SOURCE SEGMENT — Paperclip: Hire AI Agents Like Employees (Live Demo)01 THE IDEA
As AI agent orchestration platforms proliferate (Paperclip, CrewAI, AutoGen, etc.), each agent needs specialized 'skills' — pre-built capability modules that let an agent use Remotion for video, browse the web, post to Discord, etc. Today, skills.sh is an emerging hub for these but lacks robust security auditing, creating real malware/prompt-injection risk. A dedicated marketplace that combines discovery, security auditing (automated + manual), versioning, and community reviews could become the npm/PyPI of the agent skills ecosystem.
Revenue models include: charging skill publishers for featured placement or verified badges, taking a transaction fee on premium/commercial skills, offering enterprise security audit subscriptions, or white-labeling the audit infrastructure to orchestration platforms. The timing is excellent — the ecosystem is forming now and a trusted registry that gets in early will be very hard to displace once network effects kick in.
02 THE NUMBERS
$100K – $2M
$25K + 350h
$8K + 80h
6/10
5 · GROWING →
marketplace/platform product development, security engineering / code auditing, developer relations and community building, API design for skill integration, content moderation systems
03 THE VERDICT
The timing is interesting and the security gap is real, but the risk is that major orchestration platforms (Paperclip itself, OpenAI, Anthropic) build their own first-party skill stores and lock this out. The window to establish as the neutral, cross-platform registry is narrow — maybe 12-18 months. If you can execute fast and get deep integrations with multiple orchestration platforms before they consolidate, this could be very valuable. High upside but high execution-timing risk.
04 THE FIELD
- skills.shNEW · ADDED 2026-06-07
EARLY MOVER, LIMITED SECURITY INFRASTRUCTURE
Current de facto skills directory but lacks strong security auditing; mentioned directly in the video as the main option.
- npm (Node Package Manager)est. 2010STEADY · ADDED 2026-06-07
DOMINANT JS PACKAGE REGISTRY, NOT AI-SPECIFIC
Analogy/inspiration rather than direct competitor; shows the massive TAM a package registry can capture.
- Hugging Face Hubest. 2016GROWING · ADDED 2026-06-07
DOMINANT AI MODEL/DATASET HUB, EXPANDING TO AGENTS
Could expand into agent skills if they choose; current focus is models and datasets, not operational skills.