Skip to main content
SkillSafe
Apps Skills Models Docs Blog Pricing Dashboard
Signed in as

Dashboard API Keys Billing Credits Settings
Esc
↑↓ navigate ↵ open ⇧↵ view all tab source esc close View all skills →
Home / Blog / Security

Security

26 articles in this category.

Security Sep 17, 2026 15 min read

MCP Security Checklist: How to Vet and Run MCP Servers Safely in 2026

MCP is not safe by default. Twelve checks, by phase, for vetting an MCP server before install and constraining it at the call, in flight and on update.

Security Jun 17, 2026 12 min read

Arcade's $60M Round Makes Agent Permissions Infrastructure

Arcade.dev raised $60M in June 2026 for an agent authorization layer. What scoped permissions, MCP tool policy and audit trails mean for your agent stack.

Security Jun 16, 2026 12 min read

Agentjacking Turns MCP Tool Output Into an Execution Path

Agentjacking hijacks AI coding agents with a fake Sentry error. Tenet found 2,388 exposed orgs, 100+ agents running attacker code, an 85% success rate.

Security Jun 14, 2026 13 min read

IETF MCP Draft Turns Tool Safety Into a Standards Problem

An IETF Internet-Draft names 6 recurring MCP vulnerability classes and states that the MCP specification defines no normative security requirements.

Security Jun 13, 2026 14 min read

Runaway Agent AWS Bill Shows Tool Budgets Are Permissions

An AI agent provisioned five AWS instances to port-scan DN42 and ran up $6,531.30 in about 24 hours. Cost, scope and rate are tool permissions, not prompt text.

Security Jun 12, 2026 14 min read

Agent Phishing Shows Why Tool Permissions Need Identity Checks

Varonis and Imperva tested OpenClaw agents in June 2026: 2 of 4 phishing scenarios leaked live secrets. Identity-bound tool permissions are the fix.

Security Jun 11, 2026 15 min read

OpenClaw Shows Why Agents Need a Bill of Materials

An Agent Bill of Materials lists every skill, plugin, MCP server, credential and paired device an agent can reach. OpenClaw's ClawJacked bug is why you need one.

Security Jun 10, 2026 12 min read

Cisco Cloud Control Makes Agent Tool Governance Mainstream

Cisco Cloud Control puts AI agents, MCP connectors and a 50-partner tool marketplace inside infrastructure operations. What admission control that now requires.

Security Jun 9, 2026 12 min read

Vercel's Skills API Turns Agent Skills Into Infrastructure

Vercel's skills.sh API exposes 600,000+ agent skills to any tool holding an OIDC token. Pin the content hash, not the name, before you let an agent install one.

Security Jun 7, 2026 15 min read

VIPER-MCP Shows Agent Tools Need Taint Scanning

VIPER-MCP scanned 39,884 MCP server repos and confirmed 106 zero-days, 67 with CVE IDs. Agent tools need code-level taint analysis, not trust prompts.

Security Jun 6, 2026 13 min read

Microsoft ACS: Agent Controls Move Into the Runtime

Microsoft's Agent Control Specification evaluates agent policy at 8 intervention points and returns 1 of 5 verdicts: allow, warn, deny, escalate, transform.

Security Jun 5, 2026 12 min read

NSA MCP Guidance: Inventory Agent Tools Before They Drift

The NSA's May 2026 MCP guidance treats agent tooling as infrastructure: inventory every server, verify tool changes, and scan before trust drifts.

Security Jun 5, 2026 13 min read

Ruleset v2026.06.05: What 300 Sub-Agent Reviews Revealed

Ruleset v2026.06.05 adds five rules for a publisher family targeting ~/.claude and fixes eight noisy patterns. Stage 2 now reads ~6 findings per skill, not ~15.

Security Jun 4, 2026 12 min read

MCP RCE Debate: Treat Agent Plugins Like Executable Code

OX Security found a remote code execution design flaw in MCP's official SDKs: 10 CVEs, 30+ disclosures, 7,000+ exposed servers. Treat MCP servers as code.

Security May 18, 2026 21 min read

Open-OSS/privacy-filter: Typosquatting the AI Model Registry

A Hugging Face repo typosquatted OpenAI's Privacy Filter, hit #1 trending on 244K downloads in 18 hours, then ran a Rust infostealer. The full attack chain.

Security Apr 10, 2026 10 min read

Claude Mythos Found Zero-Days Everywhere. Here's Your Playbook.

Claude Mythos Preview found zero-days in every major OS and browser, one of them 27 years old, for under $50 a bug. What defenders should change now.

Security Apr 2, 2026 13 min read

ToxicSkills: What the First Large-Scale Agent Skill Audit Found

Snyk scanned 3,984 AI agent skills: 36.82% had a security flaw, 13.4% a critical one, 76 carried confirmed malware and 8 were still live at publication.

Security Mar 31, 2026 18 min read

MCP Tool Poisoning: How Hidden Metadata Hijacks AI Agents

MCP tool poisoning hides attacker instructions in tool description metadata your model reads and your UI never shows. How it works, and how to detect it.

Security Mar 29, 2026 12 min read

Langflow Exploited in 20 Hours: The AI Framework Attack Surface

Langflow's CVSS 9.3 unauthenticated RCE was exploited in the wild 20 hours after disclosure, with no public PoC. Three LangChain and LangGraph CVEs followed.

Security Mar 28, 2026 12 min read

When Trusted Packages Turn Hostile: Cascading Supply Chain Attacks

TeamPCP hid a credential stealer in a WAV file inside telnyx 4.87.1 on PyPI, using tokens stolen from litellm three days earlier. Why the cascade evades review.

Security Mar 27, 2026 13 min read

Is It Safe to Install Claude Code Skills? How to Check One First

Claude Code skills run with your files, shell and credentials. ClawHavoc put 1,184 malicious skills in one registry. How to check one before you install.

Security Mar 25, 2026 17 min read

LiteLLM's PyPI Backdoor: What It Means for the AI Skill Supply Chain

TeamPCP pushed a credential stealer into litellm 1.82.7 and 1.82.8 on PyPI via a compromised Trivy action. What it did, and why AI skills are next.

Security Mar 15, 2026 21 min read

SkillJect and the Gap in Skill Registry Security

SkillJect poisons agent skills and averages 80.7% attack success on Claude Code. Four skill scanners caught it 61.5% of the time. The 4 rules we shipped.

Security Mar 9, 2026 20 min read

ClawHavoc Campaign Explained: 1,184 Malicious AI Agent Skills

ClawHavoc was a January 2026 poisoning campaign on ClawHub: 1,184 malicious agent skills from 12 author IDs, most delivering the AMOS macOS stealer.

Security Mar 9, 2026 16 min read

Why Scanning Architecture Matters: Comparing Skill Registry Security

Three registry security models - reactive moderation, install-time scanning, and dual-side verification with a tree hash - and the attack each one misses.

Security Feb 10, 2026 9 min read

How Dual-Side Verification Protects Against Supply Chain Attacks

Dual-side verification scans a shared AI skill twice, once by the publisher and once by you, then compares both reports and a SHA-256 tree hash before install.

SkillSafe

The secured registry for AI skills.

Get Started

Quickstart Claude Code Cursor Windsurf Codex Turn a skill into an app

Product

Apps Skills Models Rankings Demos Trending Scan Pricing Docs

Security

Overview MCP Security Why SkillSafe

Company

Blog Changelog GitHub Privacy Terms Support
© 2026 SkillSafe
SOC 2 Certified HIPAA Compliant Every Shared Skill Scanned

Sign in to SkillSafe

Don't have an account?

or

By signing in, you agree to our Terms and Privacy Policy.

Create a SkillSafe Account

Already have an account?

or

By signing up, you agree to our Terms and Privacy Policy.

Verify your email

We sent a code to

Reset your password

Enter reset code

We sent a code to

Send Feedback
0 / 2000