How to read this map
Every one of the 136 rows in our public snapshot carries a single category tag. The tags describe the request a skill answers, not the technology it uses, and they are ours — no source we could reach documents an official RedSkill category taxonomy.
Two numbers per cluster matter more than the rest. The row count tells you how much supply exists. The risk split tells you what installing something from that cluster is likely to cost you if it goes wrong. Where those two disagree — plenty of supply, almost no low-risk rows — that is the cluster to approach carefully.
The eight clusters
| Cluster | Rows | Downloads | Low | Medium | High |
|---|---|---|---|---|---|
| Content creation | 27 | 7,887 | 25 | 2 | 0 |
| Publishing automation | 26 | 7,174 | 0 | 0 | 26 |
| Comprehensive operations | 23 | 35,824 | 0 | 0 | 23 |
| Login, MCP, Mac and CLI | 19 | 6,128 | 0 | 0 | 19 |
| Data and analytics | 18 | 10,089 | 0 | 10 | 8 |
| Image and card generation | 14 | 1,090 | 14 | 0 | 0 |
| Interaction and comments | 5 | 268 | 0 | 0 | 5 |
| Video download and analysis | 4 | 849 | 0 | 4 | 0 |
Four clusters contain no low-risk rows at all, and those four hold 73 rows and 71% of the downloads. If you are choosing where to start, the two clusters that never touch your account — content creation and image and card generation — are the honest starting point.
How the clusters were derived
We did not invent these clusters from a blank page. Every row in the source snapshot already carried a category label, and we kept those labels rather than re-tagging 136 rows with our own opinion — the value of the map comes from being reproducible, not from being clever. What we added is the interpretation: reading each label as a statement about what a skill does to your account, and checking that reading against the risk column.
The clustering is stable in one useful sense. Adding rows to a cluster rarely changes its risk profile, because the risk profile follows from what the cluster is for. A publishing automation row is High whether there are ten of them or a hundred, for the simple reason that publishing is the action being automated.
What each cluster tells you to do next
- Start in a cluster with low-risk rows. Content creation and image and card generation both contain rows that never touch your account, which makes them the only sensible place to learn how installs behave on your machine.
- Read the file, not the cluster. The cluster tells you what kind of outcome to expect. The
SKILL.mdtells you whether the author built in a confirmation step, and that difference matters more than the label. - Treat a popular cluster as a warning, not a recommendation. Comprehensive operations holds 52% of all downloads in the snapshot and every single row in it is High risk. Popularity in this ecosystem is a signal about ambition, not about safety.
- Do not read thin supply as safety. Video download and analysis has only four rows. A cluster with almost no supply is one where nobody has stress-tested the approach yet, which is its own kind of risk.