Skip to content

Security1 publisher3 min readPublished

Agent skills load at runtime with no signing, no provenance, and an 82% marketplace pass rate

Nine of eleven MCP marketplaces accepted proof-of-concept malware with zero review, and a fake agent skill cleared both Cisco's and NVIDIA's scanners to reach roughly 26,000 corporate agents.

The Watch · Security desk

Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

Illustration accompanying Agent skills load at runtime with no signing, no provenance, and an 82% marketplace pass rate
Generated illustration

What happened

  • AI agents load third-party skills and MCP servers at runtime, inheriting the user's email, files, and system access.
  • The agent skill and MCP ecosystem shipped with none of the supply-chain controls open source spent 15 years building: no mandatory authentication, no cryptographic signing, no provenance verification, no publisher vetting.
  • Nine of eleven MCP marketplaces accepted unvetted proof-of-concept malware with zero review.
  • The proof-of-concept malware was accepted by about 82 percent of the MCP marketplaces tested.
  • Two of the eleven MCP marketplaces tested did not accept the unvetted proof-of-concept malware.

Compiled by The WatchSomething wrong?How this is made

Why it matters

Figures cited on SC World's Security Weekly News #607 put measurements on a gap operators have been describing anecdotally for months: AI agents load third-party skills and MCP servers at runtime while inheriting the user's email, files and system access [1]. The same segment notes the ecosystem shipped without the supply-chain controls open source spent fifteen years assembling: no mandatory authentication, no cryptographic signing, no provenance verification, no publisher vetting [2].

That is not a list of nice-to-haves. It is the entire set of mechanisms that makes it possible to answer, after an incident, the question of who published the code that ran on your endpoint.

The distribution layer has already been tested. Nine of eleven MCP marketplaces accepted unvetted proof-of-concept malware with zero review [3], which is an acceptance rate of about 82 percent across the marketplaces tested [4] and leaves two that did not wave it through [5]. Marketplaces are the closest thing this ecosystem has to a package registry, and four out of five of them are functioning as file hosts.

Detection did not compensate. A fake agent skill passed both Cisco's and NVIDIA's scanners and reached approximately 26,000 corporate agents [6]. Two vendors with security scanning products in market did not catch it, and the blast radius was five figures of agents inside companies. Whatever assurance is being sold on top of this ecosystem, it is not currently a substitute for provenance.

The foundations are also carrying defects. OX Security found more than ten critical CVEs in Anthropic's own MCP SDKs, affecting 200,000 servers, according to the same segment [7]. Critical bugs in a young SDK are unremarkable in isolation. What makes this different from an ordinary library advisory is that there is no signing or provenance layer above it [2], so the usual remediation path of identifying affected builds and their publishers is largely unavailable.

Put the three data points in sequence and the shape is familiar to anyone who worked through the early package-manager years: a fast-growing distribution channel, no publisher identity, scanners doing the work that registries should be doing, and a runtime that grants inherited access by default [1]. The difference is that a compromised npm package usually needed a build step and a deploy to reach production. A skill loaded at runtime with the operator's own mail and filesystem access does not [1].

What to watch. First, whether any of the eleven marketplaces move to mandatory signing and publisher identity rather than post-hoc takedowns, and whether the two that held the line publish their review criteria [3][5]. Second, whether Cisco or NVIDIA disclose detection rates for skill and MCP-server content after the bypass [6], since a scanner with an unpublished false-negative rate is an unpriced control. Third, patch uptake on the Anthropic MCP SDKs, which is the one number that will indicate whether 200,000 servers can actually be reached by a fix [7]. Fourth, and most practical inside your own estate: whether you can currently produce a list of which skills and MCP servers your agents loaded last week, and who published them.

Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories