Invest1 distinct publisher3 min readPublished
OWASP's v1.0 standard says the payload is prose and the permissions belong to the host agent, which is another way of saying the SAST and SCA licences already on the books scan straight past the thing teams are installing this quarter.
The Investor · Invest desk
Compiled by The InvestorSomething wrong?How this is made
For anyone holding a security budget, the key detail is that this mechanism requires no exploit at all: a skill is a folder with a SKILL.md inside it, carrying a metadata header, instructions in plain English, and whatever scripts the job needs [2], the prose is the payload rather than the code [3], and the whole thing executes on whatever authority the host agent already holds [4]. Rob Joyce, formerly the NSA's cybersecurity director, describes the category as access that is not an exploit at all but a legitimate mechanism nobody watches [12]; Jason Clinton, formerly Anthropic's CISO, calls the same property delegated authority and puts the answer at boundary control [17]. Trail of Bits has already shown skills walking past scanners [16]. A static analyser returns nothing here, because there is nothing in this pattern for it to flag.
Then there is the sizing problem, which is worse than thin data. The USENIX Security 2026 study went through 98,380 marketplace skills and confirmed 157 malicious ones [5], a rate of roughly one in 627, or 0.16% [1]. A separate reference corpus of 96,096 skills, filed as a data contribution to the project repository, reported 751 malware findings [7], one in 128, or 0.78% [2]. That is about 4.9 times the first rate [3] on a corpus 2.3% smaller [4]. The two are not counting the same object (confirmed malicious skills against malware findings), which is exactly why any single number a CISO takes to a board here is a definitional choice dressed as a measurement. The 157 skills carried 632 separate vulnerabilities between them [6], so even the narrow count multiplies once you get inside it.
Against those censuses, set one campaign. ClawHavoc, in January 2026, pushed 1,184 malicious skills from 12 publisher accounts that all reported to the same command-and-control address [8]: 98.7 skills per account [5], and 7.5 times the malicious total the academic study confirmed across its entire 98,380-skill sweep [6]. Twelve accounts outproduced a marketplace-wide audit.
Ken Huang, who leads the project and runs DistributedApps.ai [11], puts the gap as a distribution channel with npm's reach and none of npm's decade of security infrastructure, meaning no signing, no provenance, and no shared vetting between registries [10]. That is a statement about what to purchase, not just what to build. Signing and provenance are registry-level plumbing, not a seat licence, and the standard shipping its own working code for signature verification, behavioural sandboxing, dependency pinning and integrity checking [14] is an admission that nobody is currently selling the control.
This is probably wrong, but the marginal dollar belongs at install-time admission rather than detection, because 1,184 skills from 12 accounts [8] falls to publisher-level provenance while reading intent out of English remains unsolved [3]. One counterargument holds that platform operators and frontier labs are named audiences for the document [9], and if they ship signed-skill enforcement natively within a release or two, every bespoke scanning build becomes stranded spend. The third path is duller and likelier, which is that the mapping onto AISVS, ASVS, ISO/IEC 42001, NIST AI RMF and four other frameworks [13] lets teams answer the questionnaire by cross-reference and change nothing at install time. What would falsify the thesis: a vendor demonstrating prose-intent detection with a false-positive rate low enough to gate installs, at which point allowlisting is the wasted build.
Ranked by verification strength, evidence, and original report placement.
The OWASP Agentic Skills Top 10 project released version 1.0 of its standard in Las Vegas on August 17, 2026, following Black Hat USA and DEF CON 2026.
A skill is a folder containing a SKILL.md file: a short metadata header, instructions in plain English, and whatever scripts and resources the job needs; an agent reads it and acts on it.
Skill instructions are prose, not code, so tools built to scan code walk straight past them.
A skill runs with the host agent's permissions, not with permissions of its own.
The ten risks are written for security teams deciding what an organization may install, developers building skills, marketplaces shipping them, and the frontier labs whose agents load and run them.
Ken Huang said the ecosystem had a distribution channel with npm's reach and none of npm's decade of hard-won security infrastructure: no signing, no provenance, no shared vetting between registries.
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 28, 2026
Follow any of these and your For You feed starts watching them — no settings page required.
build
MCP's roadmap fast-tracks five priorities and quietly queues everything else1 distinct publisher
security
The disclosure pipeline is triaging itself: 20,700 new CVEs, 10% more exploitation1 distinct publisher
build
PyRIT went read-only in March. The four tools left do not overlap the way the guides assume.1 distinct publisher
product
Rillet's $100M reads as proof mid-market ERP is rip-and-replace, mostly at the cheap end1 distinct publisher
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Free document, borrowed numbers
What the standard contains is checkable in an afternoon: the whitepaper is linked, the ten AST entries are listed, the framework mappings and the shipped verification code are there to be opened. What the standard rests on is not. The USENIX census, the 96,096-skill corpus, the Trail of Bits and Air findings and ClawHavoc all arrive as citations inside the announcement, and the two prevalence numbers disagree by a factor of five with no word on method. Ken Huang's Substack is also the only place this story appears at all.
Endorsed on day one, installed by no one yet
Eleven days separate publication from our coverage, and the only movement visible in that window is quotation. NIST, Microsoft and Air describe the framework as needed, not as running. No marketplace says it is enforcing AST02, no lab says its agents check signatures, no security team reports an inventory built against AST01–AST10. The measurable activity in this ecosystem still belongs to the other side: roughly a hundred thousand skills in circulation and twelve accounts that shipped 1,184 bad ones in a month.
'Poisoned at scale' meets one in 627
Microsoft's Omar Turner calls the ecosystem poisoned at scale; the release's own best census puts confirmed malicious skills at 0.16%, about one in 627. Both can hold — ClawHavoc alone outshipped that census by 7.5 times, and a single skill running with your agent's credentials is enough — but 'the first framework to treat the behavior layer as an attack surface' is superlative doing work the base rates do not do for it. The unshowy part of the release needs no inflation at all: the instructions are prose, the permissions are the agent's, and no scanner you own reads either.
The author, the venue, and the subscribe line
This is a press release published by the man it quotes first, on his own Substack, above an invitation to subscribe for daily agentic-AI signal. Huang leads the project and runs DistributedApps.ai; the co-lead list runs through Air, Wyze and Qorvex; the endorsement block is security leadership at Microsoft and Air, companies whose products live in exactly the gap the document describes. Working against that: the standard costs nothing, the license is open, and the whitepaper is there to be argued with.
Checkable document, unchecked world
Split the story in two and the confidence splits with it. The document side is solid — dated, licensed, linked, and the arithmetic on both censuses divides cleanly. The world side is one issuer's word: who was breached, how many skills are dirty, whether 'malware findings' and 'confirmed malicious' mean the same thing, and whether anyone will run this. Until a second outlet or the study authors speak, treat the mechanism as established and the magnitudes as provisional.