Skip to main content
SkillSafe
Apps Skills Models Docs Blog Pricing Dashboard
Signed in as

Dashboard API Keys Billing Credits Settings
Esc
↑↓ navigate ↵ open ⇧↵ view all tab source esc close View all skills →
Home / Blog / #scanning

#scanning

4 articles with this tag.

Security Jun 9, 2026 12 min read

Vercel's Skills API Turns Agent Skills Into Infrastructure

Vercel's skills.sh API exposes 600,000+ agent skills to any tool holding an OIDC token. Pin the content hash, not the name, before you let an agent install one.

Security Jun 7, 2026 15 min read

VIPER-MCP Shows Agent Tools Need Taint Scanning

VIPER-MCP scanned 39,884 MCP server repos and confirmed 106 zero-days, 67 with CVE IDs. Agent tools need code-level taint analysis, not trust prompts.

Security Mar 9, 2026 16 min read

Why Scanning Architecture Matters: Comparing Skill Registry Security

Three registry security models - reactive moderation, install-time scanning, and dual-side verification with a tree hash - and the attack each one misses.

Security Feb 10, 2026 9 min read

How Dual-Side Verification Protects Against Supply Chain Attacks

Dual-side verification scans a shared AI skill twice, once by the publisher and once by you, then compares both reports and a SHA-256 tree hash before install.

SkillSafe

The secured registry for AI skills.

Get Started

Quickstart Claude Code Cursor Windsurf Codex Turn a skill into an app

Product

Apps Skills Models Rankings Demos Trending Scan Pricing Docs

Security

Overview MCP Security Why SkillSafe

Company

Blog Changelog GitHub Privacy Terms Support
© 2026 SkillSafe
SOC 2 Certified HIPAA Compliant Every Shared Skill Scanned

Sign in to SkillSafe

Don't have an account?

or

By signing in, you agree to our Terms and Privacy Policy.

Create a SkillSafe Account

Already have an account?

or

By signing up, you agree to our Terms and Privacy Policy.

Verify your email

We sent a code to

Reset your password

Enter reset code

We sent a code to

Send Feedback
0 / 2000