SKILL.md Is the New package.json — Treat Your Skill Library Like the Supply Chain It Is
Agent skills are unsigned, executable third-party code — a supply chain most teams install on vibes. How to govern your skill library like one.
10 posts tagged with “appsec”
Agent skills are unsigned, executable third-party code — a supply chain most teams install on vibes. How to govern your skill library like one.
Anthropic just open-sourced its AI "defender's loop." The real lesson isn't about C code — it's that the bottleneck moved from finding vulnerabilities to trusting what your agents tell you, and that's a governance problem you own.
An automated audit gave us nine recommendations for being 'agent-ready.' We shipped three and deliberately failed the other six — because a security firm's agent-readiness is measured by signal honesty, not checkbox coverage.
Traditional SAST, DAST, and SCA tools were built for request-response architectures. Agent-first systems have vulnerability classes these tools were never designed to detect — and independent research just confirmed it.
Ambiguous specifications aren't just a project management problem anymore. In agent-first architectures, every gap in a spec is a potential security boundary violation — and the agent won't tell you it's guessing.
OWASP released its first Top 10 for Agentic Applications. Here's what each risk means, why traditional AppSec frameworks fall short, and how to start securing your AI agents today.
What a security engagement with Atypical Tech actually looks like — from the first call to the final deliverable. No mystery, no overhead, no surprises.
Every tool an agent can call is an attack surface. In agent-first architectures, the integration layer is the primary security boundary — and most teams aren't treating it that way.
How the Safe Autonomy framework applies to vulnerability triage, alert correlation, compliance evidence, and security testing. AI agents can multiply your security team—if you build the right guardrails.
Right-sized security for seed-to-Series-B. What actually matters, what can wait, and the mental model that scales.