Skip to main content
SkillSafe
Apps Skills Models Docs Blog Pricing Dashboard
Signed in as

Dashboard API Keys Billing Credits Settings
Esc
↑↓ navigate ↵ open ⇧↵ view all tab source esc close View all skills →
Home / Blog / #plugins

#plugins

14 articles with this tag.

Ai Tools Sep 17, 2026 17 min read

Agent Skills vs MCP vs Plugins: What Each Is and When to Use It

An agent skill is a SKILL.md folder an agent loads on demand; MCP is a live protocol to tools and data; a plugin bundles both. What to use when.

Security Jun 17, 2026 12 min read

Arcade's $60M Round Makes Agent Permissions Infrastructure

Arcade.dev raised $60M in June 2026 for an agent authorization layer. What scoped permissions, MCP tool policy and audit trails mean for your agent stack.

Security Jun 16, 2026 12 min read

Agentjacking Turns MCP Tool Output Into an Execution Path

Agentjacking hijacks AI coding agents with a fake Sentry error. Tenet found 2,388 exposed orgs, 100+ agents running attacker code, an 85% success rate.

Security Jun 14, 2026 13 min read

IETF MCP Draft Turns Tool Safety Into a Standards Problem

An IETF Internet-Draft names 6 recurring MCP vulnerability classes and states that the MCP specification defines no normative security requirements.

Security Jun 13, 2026 14 min read

Runaway Agent AWS Bill Shows Tool Budgets Are Permissions

An AI agent provisioned five AWS instances to port-scan DN42 and ran up $6,531.30 in about 24 hours. Cost, scope and rate are tool permissions, not prompt text.

Security Jun 12, 2026 14 min read

Agent Phishing Shows Why Tool Permissions Need Identity Checks

Varonis and Imperva tested OpenClaw agents in June 2026: 2 of 4 phishing scenarios leaked live secrets. Identity-bound tool permissions are the fix.

Security Jun 11, 2026 15 min read

OpenClaw Shows Why Agents Need a Bill of Materials

An Agent Bill of Materials lists every skill, plugin, MCP server, credential and paired device an agent can reach. OpenClaw's ClawJacked bug is why you need one.

Security Jun 10, 2026 12 min read

Cisco Cloud Control Makes Agent Tool Governance Mainstream

Cisco Cloud Control puts AI agents, MCP connectors and a 50-partner tool marketplace inside infrastructure operations. What admission control that now requires.

Security Jun 9, 2026 12 min read

Vercel's Skills API Turns Agent Skills Into Infrastructure

Vercel's skills.sh API exposes 600,000+ agent skills to any tool holding an OIDC token. Pin the content hash, not the name, before you let an agent install one.

Security Jun 7, 2026 15 min read

VIPER-MCP Shows Agent Tools Need Taint Scanning

VIPER-MCP scanned 39,884 MCP server repos and confirmed 106 zero-days, 67 with CVE IDs. Agent tools need code-level taint analysis, not trust prompts.

Security Jun 6, 2026 13 min read

Microsoft ACS: Agent Controls Move Into the Runtime

Microsoft's Agent Control Specification evaluates agent policy at 8 intervention points and returns 1 of 5 verdicts: allow, warn, deny, escalate, transform.

Security Jun 5, 2026 12 min read

NSA MCP Guidance: Inventory Agent Tools Before They Drift

The NSA's May 2026 MCP guidance treats agent tooling as infrastructure: inventory every server, verify tool changes, and scan before trust drifts.

Security Jun 4, 2026 12 min read

MCP RCE Debate: Treat Agent Plugins Like Executable Code

OX Security found a remote code execution design flaw in MCP's official SDKs: 10 CVEs, 30+ disclosures, 7,000+ exposed servers. Treat MCP servers as code.

Security Mar 27, 2026 13 min read

Is It Safe to Install Claude Code Skills? How to Check One First

Claude Code skills run with your files, shell and credentials. ClawHavoc put 1,184 malicious skills in one registry. How to check one before you install.

SkillSafe

The secured registry for AI skills.

Get Started

Quickstart Claude Code Cursor Windsurf Codex Turn a skill into an app

Product

Apps Skills Models Rankings Demos Trending Scan Pricing Docs

Security

Overview MCP Security Why SkillSafe

Company

Blog Changelog GitHub Privacy Terms Support
© 2026 SkillSafe
SOC 2 Certified HIPAA Compliant Every Shared Skill Scanned

Sign in to SkillSafe

Don't have an account?

or

By signing in, you agree to our Terms and Privacy Policy.

Create a SkillSafe Account

Already have an account?

or

By signing up, you agree to our Terms and Privacy Policy.

Verify your email

We sent a code to

Reset your password

Enter reset code

We sent a code to

Send Feedback
0 / 2000