frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Agent Skills – Open Security Database

https://index.tego.security/skills/
10•4ppsec•1h ago

Comments

4ppsec•1h ago
A new public database has launched to analyze the security risks introduced by AI agent skills, the capabilities that increasingly define how modern AI agents operate.

The site — available at https://index.tego.security/skills/ — presents what appears to be the first dedicated database focused on the security assessment of AI agent skills, cataloging the capabilities these modules grant to AI systems and evaluating the risks they may introduce into agent-driven workflows.

AI skills — sometimes called tools, functions, or plugins — are rapidly becoming the core building blocks of agentic AI systems. They allow language models to retrieve data, perform specialized reasoning tasks, and execute automated workflows. But this capability also introduces a new layer of attack surface that many organizations are only beginning to understand. Research examining large ecosystems of agent skills has already found that over a quarter contain at least one security vulnerability, including prompt injection vectors, privilege escalation opportunities, and data-exfiltration risks.

The new database aims to make this emerging attack surface visible.

Each skill entry includes a structured security analysis designed to help practitioners understand how a capability might be abused inside real agent deployments. The assessment process uses a multi-dimensional security methodology combining automated scanning, specialized AI models trained to analyze agent behavior, and manual security review.

Rather than simply flagging potentially dangerous code patterns, the analysis follows a practical philosophy: instructions and behaviors are evaluated within the context of the skill’s intended purpose. This allows the review process to distinguish between normal operational capabilities and behaviors that could realistically be exploited by attackers manipulating an AI agent’s reasoning process.

The project reflects a broader shift occurring in AI system security. As AI agents move beyond text generation into task execution and autonomous workflows, the security boundary is increasingly defined by the capabilities those agents can invoke.

In this model, skills effectively become the execution layer of AI systems, capable of: • influencing agent decision-making • injecting context into reasoning processes • triggering automated actions • exposing data through tool outputs • interacting with other agents

Security researchers are beginning to recognize that these capabilities introduce attack patterns with few direct parallels in traditional software, including indirect prompt injection through retrieved content and confused-deputy attacks caused by agent tool invocation.

By cataloging and analyzing these capabilities, the database aims to provide security teams with a clearer understanding of how agent behavior translates into security risk.

The resource is publicly accessible and is expected to expand as the ecosystem of AI agent skills continues to grow.

The company behind the project, Tego AI, is currently operating in stealth mode while developing security technologies focused on the emerging agentic AI ecosystem.

Trump Airs a House Republican's Terminal Diagnosis, Claiming to Have Reversed It

https://www.nytimes.com/2026/03/16/us/politics/trump-neal-dunn-terminal-diagnosis-johnson.html
1•duxup•2m ago•1 comments

A reminder to check your inactive account passwords

https://shub.club/writings/2026/march/rotate-your-passwords/
1•forthwall•2m ago•0 comments

The Last Quiet Thing

https://www.terrygodier.com/the-last-quiet-thing
1•JumpCrisscross•3m ago•0 comments

As India seeks Hormuz safe passage, Tehran asks for return of seized tankers

https://www.reuters.com/world/india/india-seeks-hormuz-safe-passage-tehran-asks-return-seized-tan...
1•JumpCrisscross•4m ago•0 comments

Robot dogs are protecting data centers. Operators are seeing payoffs

https://www.businessinsider.com/robot-dogs-quadruped-data-center-security-boston-dynamics-ghost-r...
1•mikhael•4m ago•0 comments

Show HN: Aelitium – Git-style verification for LLM outputs

https://aelitium.com
1•catarina_eng•5m ago•0 comments

Ask HN: Okara's new AI CMO: Will this solve the marketing problem?

1•nazbasho•7m ago•1 comments

"Gemini AOS": Google's Next Android, Hidden in ATI Silicon

https://guanghuimao.substack.com/p/gemini-aos-googles-next-android-hidden
2•Ati985•8m ago•0 comments

Avalonia WebView Is Now Free and Open Source

https://github.com/AvaloniaUI/Avalonia.Controls.WebView
2•sltr•8m ago•0 comments

Google scraps AI search feature that crowdsourced amateur medical advice

https://www.theguardian.com/technology/2026/mar/16/google-scraps-ai-search-feature-that-crowdsour...
2•geox•8m ago•0 comments

Video Conferencing with Postgres

https://planetscale.com/blog/video-conferencing-with-postgres
1•thunderbong•8m ago•0 comments

tables and views

https://web.archive.org/web/20060710204054/http://www.kx.com/a/k/examples/table.k
1•tosh•9m ago•0 comments

Show HN: Ziex – A full-stack web framework for Zig

2•nurulhudaapon•9m ago•0 comments

Show HN: We Built Private Post-Training and Inference for Frontier Models

https://www.workshoplabs.ai/blog/private-post-training
4•oscarmoxon•12m ago•1 comments

Show HN: SmartVPN: A VPN That Hides in Plain Sight over WebSockets

https://typescript.guru/smartvpn-a-vpn-that-hides-in-plain-sight-over-websockets/
1•PhilKunz•13m ago•0 comments

Show HN: LLM Memory Storage that scales, easily integrates, and is smart

https://github.com/colinulin/mind-palace
2•pocketcolin•15m ago•0 comments

Agents over Bubbles

https://stratechery.com/2026/agents-over-bubbles/
2•jonbaer•16m ago•0 comments

Lines of Code as a Productivity Metric in the AI Era

https://keegan.codes/blog/lines-of-code-as-a-productivity-metric-ai-era
1•keegandonley•17m ago•0 comments

Show HN: Stop renting AI – run AI workers on your own dedicated node

https://ainode.sh
1•rzessski•19m ago•1 comments

Northstar CUA Fast, open source 4B CUA model

https://www.tzafon.ai/blog/northstar-cua-fast
1•publius_•20m ago•0 comments

How Tenaciously Palantir Courted Switzerland

https://www.republik.ch/2026/02/18/how-tenaciously-palantir-courted-switzerland
1•sschueller•22m ago•0 comments

Beside

https://aplwiki.com/wiki/Beside
1•tosh•22m ago•0 comments

2 Days to Ship: Codex-Authored Metal Compute Shaders in Draw Things

https://engineering.drawthings.ai/p/2-days-to-ship-codex-authored-metal
1•liuliu•23m ago•0 comments

Open Decision-Making (2021)

https://web.stanford.edu/~ouster/cgi-bin/decisions.php
1•otoolep•23m ago•0 comments

Show HN: Tic-Tac-Word – Can you beat yourself in this tic-tac-toe word game?

https://www.tictacword.com
4•onion92•24m ago•1 comments

Autoresearch for SAT Solvers

https://github.com/iliazintchenko/agent-sat
2•chaisan•25m ago•1 comments

Agents are not thinking: a behavioral study of pwning sonnet

https://technoyoda.github.io/pwning-claude.html
2•sci-genie•25m ago•0 comments

Embedding TeX Hyphenation Patterns for 30 Languages in a 1.1 MB Rust Automaton

https://laurmaedje.github.io/posts/hypher/
2•PaulHoule•25m ago•0 comments

MacBook Neo can be modded to run faster, but you probably shouldn't

https://appleinsider.com/articles/26/03/16/macbook-neo-can-be-modded-to-run-faster-but-you-probab...
4•gslin•27m ago•0 comments

Show HN: Smart glasses that tell me when to stop pouring

https://github.com/RealComputer/GlassKit/tree/main/examples/rokid-overshoot-openai-realtime
3•tash_2s•27m ago•0 comments