Morning Edition · Monday, September 14, 2026Published at 2:22 AM EDT · New York
Across three scanners applied to a public agent skill registry, any pair agreed on at most 10.4% of their combined detections, and 81.9% of flagged skills were caught by one scanner alone.

A preprint posted on September 14, Scan the Skill, Govern the Action, starts from a measurement that undermines how agent skill registries currently work. Security scanning of published skills, the packaged instructions and tools that agent…
Track frontier labs, chips, export controls, model releases, regulation, and AI infrastructure.
The Global Intelligence Brief stays free.
Part of a tracked trend
The Agent Skill Supply Chain Becomes an Attack Surface
As agents load third-party skills, tools and MCP servers at runtime, the gap between what a skill advertises and what it actually does becomes a recurring security failure mode, driving registries, attestation and zero-trust verification into the agent stack the way package signing came to software repositories.
Start a discussion in Townsquare.
More from this edition
Comments
0No comments yet.