← Back to all episodes
August 24, 2026 — #26

Nobody Owns the Skill Layer

#26 · ~13 min · Curated by Asaf Nakash

0:00 / 0:00
Listen on: Spotify Apple Podcasts Amazon Music YouTube RSS

Stories This Week

Curator's Corner

When a browser extension turns malicious, there is someone to call. Google can pull the listing, revoke the signature, and push the removal out to every machine that installed it. Unglamorous machinery, and it works. Ask the same three questions about the skills your agents loaded this morning and the room goes quiet. Who reviews them? Who signs them? Who can pull one back?

I have not found an answer, and this week made the gap harder to look away from.

Start with the fact that OWASP had to write a new list at all. The existing lists cover the model, and the protocol an agent uses to reach its tools. Neither covers the packaged behaviour that decides what those tools get used for. And the format proposed alongside the list reads as a request, field by field, for things that do not exist yet: a publisher identity, a signing key, a hash of the package, a declared permission set, a scan record. You do not draft that manifest for a layer that already has provenance.

Then the experiment. In June, Air Security researchers built a skill in under an hour that genuinely did what it promised, generating landing pages for non-technical staff. Its instructions sent the agent to fetch setup documentation from a domain they controlled. Then they collected the two signals people use to judge a skill. Scanner approval came free, because scanners read files and the payload was a link. Stars they borrowed, opening a pull request into a plugin marketplace repository with roughly 36,000 stars and a welcoming contribution policy: "after a few anxious days, it got merged." They ran an Instagram ad, swapped the documentation, and victim emails started arriving. Twenty-six thousand agents, including corporate ones. OWASP now cites that work as the real-world evidence behind its risk for untrusted external instructions. Niv Hoffman co-authored the research and is one of eight co-leads on the OWASP project.

📰 Get the full newsletter — every story, every source, every week