Security1 distinct publisher2 min readPublished
Skills, hooks, repository instruction files and MCP servers all steer what an agent reads and runs, and governance that records only the application name leaves no inventory of the third-party code shaping builds.
The Watch · Security desk
Compiled by The WatchSomething wrong?How this is made
Follow any of these and your For You feed starts watching them — no settings page required.
leadership
Anthropic folds half of Claude Code's summer boost into the permanent weekly limit2 distinct publishers
leadership
Anthropic's own telemetry: 93% of permission prompts approved. Budget for blast radius, not reviewers1 distinct publisher
security
Anthropic's Compliance API now logs the Claude Code sessions running on inherited developer credentials1 distinct publisher
build
Spline V2 turns the 3D editor into an endpoint, with the desktop app as the only door1 distinct publisher
Each link in the chain is defensible on its own. A developer installs a plugin. The plugin loads a Skill. The Skill instructs the agent to call an MCP tool. The MCP server uses that developer's identity to reach another system. A hook records, modifies or forwards the result [5]. There are five links in that chain. An approval that stops at the application name accounts for one of them. That leaves four that no inventory holds [6].
The plugin layer is what makes that compound. One plugin can bundle Skills with connectors, subagents, hooks and MCP server configuration, so a single install decision can add several suppliers at once [4]. Of the review questions the article proposes, the one existing change control cannot answer is what can change after approval [13]. Lockfiles and version pins answer that for libraries, but they say nothing about a Skill pulled from a marketplace, a hook committed to a repository after review, or an MCP server whose tool descriptions are rewritten on the server side [4].
The pace here is set by what the article does not supply. It asserts that researchers are finding failures at discovery, install, review, runtime and repository configuration [11], with no incident, researcher, CVE or date attached in the text supplied [12]. That makes this inventory work rather than emergency patching, and the useful unit of inventory is per workspace: which Skills, hooks, subagents and MCP servers are present in this repository and this developer's configuration today, and who put them there [4].
There is a second-order effect worth naming. The current generation of agents can inspect a repository, edit files, execute shell commands, query internal systems, open pull requests and run for long stretches with limited supervision [16]. An instruction file read by that agent is not advice aimed at a human; it is input read by something holding a shell. Shadow AI began as a label for employees using an unapproved model or pasting enterprise data into an unapproved chatbot [15]. The version that touches build integrity is different: it sits inside the approved tool, installed a folder at a time by developers with commit access [3].
Ranked by verification strength, evidence, and original report placement.
A Hacker News expert-insights piece, "Shadow AI Is Now Hiding Inside Sanctioned AI Tools", argues that tools such as Claude Code, OpenAI Codex, Claude Cowork and GitHub Copilot are becoming extensible agent runtimes rather than code suggestion engines.
Skills, plugins, hooks, repository instructions and MCP servers can influence what the agent reads, which tools it selects, what commands it runs, and where enterprise data is sent.
Most AI governance programs stop at approving the application, and very few can say everything that has been installed inside it.
Definitions given: a Skill is a folder of instructions, scripts and resources; a plugin is the packaging layer that can bundle Skills with connectors, subagents, hooks and MCP server configurations; an MCP server gives the agent access to external tools, databases, APIs and context; a hook runs a command, HTTP request or model prompt at a defined point in the agent lifecycle; a repository instruction file changes how the agent behaves for a particular codebase.
The transitive trust chain described: the user trusts the plugin; the plugin loads a Skill; the Skill instructs the agent to call an MCP tool; the MCP server uses the user's identity to access another system; a hook records, modifies or forwards the result.
No new binary has to appear for the agent's behavior to change.
Distinct publishers with included, body-backed reporting in this cluster.
1 article · September 2, 2026
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Checkable mechanics, uncheckable urgency
The reporting splits cleanly in two. Its descriptive half — what a Skill, plugin, hook, MCP server and repository instruction file are, and what each can reach — is the kind of thing an engineer can verify against product documentation in an afternoon, which is why it holds up. Its empirical half is one sentence: researchers 'are already finding failures.' No researcher, no product, no date, no identifier. The heading above that sentence promises four agent supply-chain problems already showing up and the text we have names none of them.
Nothing counted
Not one number appears. No count of developers running self-installed Skills, no marketplace install figures, no share of repositories carrying instruction files, no breach, no disclosed customer. The Hacker News asserts that sanctioned agents are already carrying unsanctioned extensions and then moves to advice. We will not put a score on a trend line drawn freehand.
Real mechanism, asserted timeline
Overstated, but not by much and not everywhere. The plumbing is genuinely as described, and the arithmetic of the trust chain is fair: five links, one of which an application-level approval names. Where the piece runs ahead of what it shows is in its verbs — 'already showing up', 'already finding failures' — and in the coinage of Shadow AI inside approved AI, a phrase doing rhetorical work that rests entirely on the unnamed findings underneath it.
Contributed column, checklist ending
This ran in The Hacker News's expert-insights slot rather than its newsroom, and it lands exactly where commercially sponsored security writing lands: inventory the extension layer, stand up an organization-managed registry, review the graph, record publisher and commit. No vendor is named anywhere in what we were given, so we cannot say who books revenue when a reader works through that list — only that the argument is shaped like a product's problem statement. The four companies whose runtimes are named get no chance to answer.
Sure of the argument, unsure of the world
We are on firm ground saying what this piece argues and where it stops arguing. We are on thin ground beyond that: one publisher, no independent corroboration, no adversarial comment, and a text that breaks off mid-sentence inside its third recommendation, so part of the advice sits outside our view. Enough to take the mechanism seriously; not enough to size the exposure.