Skip to content
Trending storyDeveloping

Agent Skills Should Be Treated as Supply Chain Components

1 article1 sourcesince Oct 8Last article Yesterday ·

Overview

AISummary of 1 article

Tessl argues, in a talk at AI Native DevCon London reported on its blog, that agent skills should be treated as supply chain components because they can shape how AI agents behave.

Skills can be markdown instructions bundled with supporting files, so the author says reviewing the main SKILL.md file alone is not enough; risks can sit in supporting files, in later updates, and in workspace trust settings.

The author identifies the core danger as the combination of private context, untrusted content, and external communication. He cites research that scanned roughly 4,000 public skills and found issues including malware-like behavior. These are the author's and the cited research's claims as reported by Tessl, not independently verified findings.

Written by AI from the articles below · updated Oct 8, 8:02 PM ET

Check the sources:

Article timeline

Follow the coverage from different perspectives. Times are ET.

Oct 8
  1. Tessl Blog
    Agent Skills Should Be Treated as Supply Chain Components

    AITessl's talk at AI Native DevCon London argues that agent skills, which can be markdown files with instructions and bundled material, act as supply chain components that can shape agent behavior. The author says reading SKILL.md once is insufficient because risks can sit in supporting files, updates, and workspace trust settings. He identifies the danger as the combination of private context, untrusted content, and external communication, and cites research scanning roughly 4,000 public skills for issues including malware-like behavior.

Heat trend

Not enough continuous observations to show a trend yet.