What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Agent skills are becoming easier to share, but that does not answer the practical question: “Should I install this skill?” In a September 25, 2026 essay, William Chiu argues that distribution is maturing faster than the evidence teams need to judge a skill’s safety, permissions, integrity and usefulness. His proposed answer—a shared trust loop—is a design proposal, not an established standard. A scan can inform an install decision; it cannot, by itself, prove a skill safe or effective in every setting.
What “distribution is solved” means—and what it does not
Chiu points to popular skill repositories, Cloudflare’s security-audit playbook distributed as a skill, and Anthropic’s agent-onboarding repository as signs that skills are becoming a normal way to distribute agent instructions and supporting files. His claim that distribution is “solved” is an interpretation of that trend, not a measured consensus or proof that every team can find, install and maintain skills reliably.
The underlying concern is about the decision after discovery. A skill is an input to a software supply chain: it may contain instructions as well as supporting files, and the material can shape what an agent does. Teams need more than a discoverable download to decide whether to accept that input, restrict its permissions, track changes and revisit it when problems appear. Chiu argues that scanners alone do not create a common install decision, proof badge, CI requirement or remediation loop.
What the proposed trust loop would do
Chiu describes the missing loop as: “lint → permission manifest → 0–100 score + badge → CI gate.” Each element addresses a different part of adoption:
PC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11Crashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minute#1 Best Overall
- FIDO2 & Passkey Ready: Business-ready and FIDO2 L1 certified. This key is supported by major management suites and is ideal for both individual and enterprise deployment. Works seamlessly with Gmail, Facebook, GitHub, Dropbox, Coinbase, and more.
- Universal Connectivity (USB-A ): Features a built-in USB-A connector—simply unfold the key and plug it into your compatible PC or laptop for seamless authentication on the go.
- Dedicated Manager App: Use the Thetis Manager App for the initial hardware PIN setup. Setting the PIN on the device first ensures a smooth registration process. Once the PIN is configured, you can begin registering the key across your favorite FIDO2-compatible online services.
- Ultra-Durable & Portable: Featuring a rotating metal cover, this key is water, crush, and tamper-resistant. It fits easily on a keychain and requires no batteries or network connectivity.
- Check FIDO2 compatibility before purchase - Known limitations: ID Austria is not supported (requires FIDO2 Level 2). Windows Hello login only works with Windows Enterprise editions that support Entra ID, and NFC is NOT supported.
- Lint: inspect a skill for known risky patterns before accepting it.
- Permission manifest: make the skill’s expected access visible so a team can compare it with the task and its policies.
- Score and badge: summarize evidence in a form that is easier to review. A score would only be meaningful if its checks, scope and limitations were clear; a number is not proof of safety.
- CI gate: let a team apply its own release or installation policy consistently, rather than relying only on an individual’s manual review.
- Minimal-permission rewrites: reduce access or risky behavior when a finding is actionable, then check the revised artifact again.
This is Chiu’s proposed design, not a standard endorsed by a regulator or standards body. Its usefulness would depend on transparent rules, coverage of the files actually used, and a remediation process that does not treat a clean score as a guarantee.
What SkillSpector can establish
NVIDIA’s SkillSpector documentation describes a scanner that accepts individual files, directories, repositories and archives. Its checks address risks such as prompt injection, data exfiltration, privilege escalation, supply-chain issues, tool misuse and excessive agency. The documentation lists terminal, JSON, Markdown and SARIF outputs; SARIF is intended to support CI and IDE integration. NVIDIA recommends using scanning as one release gate and triaging high-severity findings.
Rank #2
- Ultra-Compact FIDO2 Security Key - Plug-and-stay or carry on a keychain. This USB-A hardware security key offers portable, always-on protection for desktop and mobile use. (Item Size: 0.75 X 0.74 IN x 0.25 IN)
- USB-A Hardware Key for All Devices - Works with USB-A ports on PC, Mac, Android, and other laptop/notebook device. Enables secure, cross-platform login with FIDO2.0 passkey support.
- FIDO Certified Security Key - Meets FIDO and FIDO2 standards. Works with Google, Microsoft, GitHub, Dropbox, and more. Please check service compatibility before purchase.
- Passwordless Login with Passkey - Supports passkey login via WebAuthn and CTAP2. Enjoy password-free sign-ins where supported. Not all websites or services currently support passkeys.
- Advanced Multi-Factor Authentication - Offers 200 FIDO2 passkey slots and 50 OATH-TOTP slots. Strong, flexible 2FA/MFA support across various apps and authentication platforms.
Those capabilities make a scan useful evidence, but the evidence is bounded: it concerns the artifact scope and rules that were checked. Before relying on a report, establish what was included—only a primary instruction file, or also scripts, references, assets and dependencies—and which checks actually ran. A report that covers one file cannot establish the safety of supporting files it never inspected. A clean result means the scanner did not report a finding under its checks; it is not a blanket guarantee that the skill is safe to install in every environment.
Security is not the same as usefulness
A skill can avoid detected security problems and still fail to help—or make an agent’s output worse. NVIDIA’s trust-pipeline documentation states: “A skill can pass every security check and still make an agent worse.” Security scanning asks whether the artifact triggers security checks; usefulness requires task-based evaluation of what changes in the agent’s behavior and results.
Quick wins for a faster PC:
Clear out junk files and repair common Windows errorsFree Scan →Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Rank #3
- FIDO2 & Passkey Ready: Business-ready and FIDO2 L1 certified. This key is supported by major management suites and is ideal for both individual and enterprise deployment. Works seamlessly with Gmail, Facebook, GitHub, Dropbox, Coinbase, and more.
- Dedicated Manager App: Use the Thetis Manager App for the initial hardware PIN setup. Setting the PIN on the device first ensures a smooth registration process. Once the PIN is configured, you can begin registering the key across your favorite FIDO2-compatible online services.
- Universal Connectivity (USB-C, USB-A, & NFC): Designed for PCs, Macs, iPhones, and Android. For mobile use, simply unfold the key, align it with your phone’s NFC antenna, and hold for a few seconds to authenticate.
- Enhanced MFA (FIDO2 & TOTP/HOTP): Strengthen your security with flexible options. Use the Manager App to access TOTP/HOTP features for accounts that do not yet support FIDO2.
- Check FIDO2 compatibility before purchase - Known limitations: ID Austria is not supported (requires FIDO2 Level 2). Windows Hello login only works with Windows Enterprise editions that support Entra ID. NFC is supported only through mobile authentication, Not MacOS/windows.
NVIDIA describes a wider pipeline that combines validation and security scanning with semantic overlap checks, live task evaluation, skill cards documenting ownership and risks, and a detached signature to check whether a published directory has changed. These forms of evidence answer different questions:
- Scan findings: Did the configured checks flag risks in the inspected scope?
- Task evaluation: Did the skill improve outcomes on the tasks used to test it?
- Ownership and risk documentation: Who is responsible for the skill, and what risks are disclosed?
- Signature: Does the published directory still match the signed version?
None substitutes for the others. In particular, a signature can help detect a change to an artifact, but it does not establish that the original artifact was safe or useful. Likewise, passing a security gate does not establish that the skill improves performance.
Rank #4
- Packing List: This doorbell removal tool set is made of high-quality metal and comes in four types and comes with two doorbell removal pins and a key ring. These kits can be hung on a key ring, making them portable and loss-proof.You will get: 8 x Security Pin Key Release Removal Tool,1 x key ring.
- Anti-slip Handle Design: It has a solid and anti-slip handle, which is easy to grasp and saves effort when using it.
- Wide Application: It could be used for replacing your lost security key to remove your Nest Hello, Arlo and Eufy Video Doorbell from its mount.It can even be used to detach part of the metal watch strap.
- Compatibility: Fits various models of video doorbell. All Arlo Video Doorbell Models, all Eufy Video Doorbell models, and all Nest video doorbell models.
- Multi Usages: With this tool, you could replicate the action of the manufacturer security pin but inserting it on either the top or bottom, dependent on model and pulling gently on the doorbell to release it.
How to decide whether to install a skill
- Define the task and permitted access. Identify what the agent needs to do and the minimum tools or data access required. Compare the skill’s declared permissions and behavior with that boundary.
- Check the artifact scope. Determine which files the scanner examined and whether scripts, references, assets and dependencies are included. Treat omitted files as unchecked, not implicitly safe.
- Read findings and triage serious ones. Review the checks and any high-severity results rather than relying on a badge or a single summary score. Follow your organization’s policy for blocking, investigating or accepting a documented risk.
- Verify provenance and integrity separately. Look for ownership and risk documentation, and use a verifiable signature where available to check that the published directory has not changed since signing.
- Evaluate the skill on representative tasks. Compare agent results with and without the skill using tasks that reflect the intended use. A security report alone cannot show whether the skill improves outcomes.
- Apply the decision in your workflow. Where supported, use machine-readable output such as SARIF with CI or IDE workflows, and define the team’s own release criteria. If a problem is fixable, reduce permissions or revise the skill and inspect the resulting artifact again.
This process does not produce certainty. It makes the basis for an install decision more explicit: what was checked, what was not checked, who owns the artifact, whether it changed, and whether it helped on the tasks that matter.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.What the 2026 vulnerability figure says
NVIDIA’s SkillSpector project page reports that 26.1% of a 31,132-skill analyzed subset contained at least one vulnerability; it also reports likely malicious intent in 5.2% of that analyzed subset. These are figures about the subset NVIDIA analyzed in 2026, not prevalence estimates for every skill in every registry. They indicate why inspection matters, but they do not tell an individual team whether a particular skill is acceptable for its intended use.
Best Value
- Ultra-Compact FIDO2 Security Key – Plug-and-stay or carry on a keychain. This USB-C hardware security key offers portable, always-on protection for desktop and mobile use.(Item Size: 0.73 X 0.60 X 0.30 inches)
- USB-C Hardware Key for All Devices – Works with USB-C ports on PC, Mac, Android, and USB-C iPhones. Enables secure, cross-platform login with FIDO2.0 passkey support.
- FIDO Certified Security Key – Meets FIDO and FIDO2 standards. Works with Google, Microsoft, GitHub, Dropbox, and more. Please check service compatibility before purchase.
- Passwordless Login with Passkey – Supports passkey login via WebAuthn and CTAP2. Enjoy password-free sign-ins where supported. Not all websites or services currently support passkeys.
- Advanced Multi-Factor Authentication – Offers 200 FIDO2 passkey slots and 50 OATH-TOTP slots. Strong, flexible 2FA/MFA support across various apps and authentication platforms.
What remains unproven about the proposed approach
Chiu reports building a Python CLI, SkillSpector v0.1, and says it produced zero false positives across 53 skills and detected 13 of 13 known-bad patterns in its test suite. These are the author’s reported day-one benchmarks; the available account does not independently establish the test methodology or reproduce the results. They should not be read as independent validation of the tool or as evidence that it detects every relevant risk.
The essay describes sandbox trial runs and single-binary distribution as roadmap items, not features available in that day-one version. More broadly, a trust loop is only as reliable as its coverage, evaluation design, provenance checks and handling of findings. A score or badge without those details could make uncertainty look settled rather than help teams manage it.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




