Glossary

Agent skills

Agent skills are packaged, reusable instructions that an AI agent loads only when a task needs them. A skill is a folder with a SKILL.md file inside, holding a short name, a description and the steps for a task, sometimes alongside scripts, reference docs and templates. Until the skill is relevant, the agent sees only its description.

The term has nothing to do with skill-based routing in contact centers, where skills are traits of human agents, like language or product expertise, used to match a customer with the right person. In the AI sense, a skill is packaged know-how. Teams use skills to teach an agent new tasks without retraining a model or rewriting its system prompt.

How agent skills work

The Agent Skills specification defines a skill as a directory containing a file named SKILL.md. The file opens with YAML frontmatter that holds a name and a description, followed by plain Markdown instructions for the task.

The folder can also hold scripts for executable code, references for longer documentation, and assets like templates. File paths resolve relative to the skill's own folder, so a skill can be copied between projects and still work.

The description does most of the heavy lifting. The agent reads it to decide whether a skill applies, so it has to say plainly what the skill does and when to use it. A vague description means a skill that never activates, or one that activates on the wrong tasks.

Why progressive loading saves context

Skills load in stages, a pattern the spec calls progressive disclosure. At startup, the agent loads only the name and description of each installed skill, which the spec puts at about 100 tokens per skill.

When a task matches a description, the agent reads the full SKILL.md body. The spec recommends keeping that under 5,000 tokens. Scripts and reference files load only when the instructions point to them.

The payoff is simple. An agent can have dozens of skills available while paying the full cost only for the one or two it's using. Loading everything upfront would crowd the context window, raise costs and pull the model's attention away from the task.

Agent skills vs tools and MCP servers

Skills are often confused with tools, but they work at a different level. A tool, exposed through tool calling, is a single function with a typed schema, like looking up an order or issuing a refund. A skill is closer to a playbook. It tells the agent how to approach a task, which tools to call in what order, and what good output looks like.

MCP servers are different again. An MCP server exposes tools and data over a protocol, and its code runs on a separately managed server. Skills are files the agent reads and, in many setups, runs locally with the user's own privileges.

The two work well together. An MCP server gives an agent access to a system. A skill teaches the agent how to use that access properly.

Common risks in third-party skills

Because a skill is both instructions and code, a third-party skill is a supply-chain dependency with two ways in. Hidden directives in the SKILL.md can override safety rules or tell the agent to send data somewhere else. Bundled scripts can collect credentials or download and run remote code.

The instructions are the bigger problem. A large study of malicious agent skills ran 98,380 skills from community registries through its pipeline, and found that 84.2% of the vulnerabilities in confirmed malicious skills sat in SKILL.md files rather than in code. Code scanners alone miss most of the risk.

The defenses look like those for any software dependency. Know who wrote a skill and who maintains it, review both its instructions and its code, pin versions so a trusted skill can't change quietly, and run it with the narrowest permissions the task allows. Skills from untrusted sources shouldn't load automatically.

What agent skills mean for customer service

For support teams, the key point is governance. A skill that changes how an agent handles refunds is a policy change, and it deserves the same review, version history and audit trail as any other policy change.

In practice, that means keeping a list of every installed skill with an owner, a version and a note on what it can touch. A skill that only formats replies needs light review. One that runs scripts or calls refund tools needs the same sign-off as a code change.

Treated that way, skills are an efficient way to give agents deep, task-specific knowledge without bloating every conversation. Treated as harmless text files, they're an easy path for untrusted instructions to reach production.

What is an Agent Operating Procedure? | Decagon Dialogues '25

For a deeper dive, download Decagon's guide to agentic AI for customer experience.

Deliver the concierge experiences your customers deserve

Get a demo