frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Agent Skills – Open Security Database

https://index.tego.security/skills/
27•4ppsec•3h ago

Comments

4ppsec•3h ago
A new public database has launched to analyze the security risks introduced by AI agent skills, the capabilities that increasingly define how modern AI agents operate.

The site — available at https://index.tego.security/skills/ — presents what appears to be the first dedicated database focused on the security assessment of AI agent skills, cataloging the capabilities these modules grant to AI systems and evaluating the risks they may introduce into agent-driven workflows.

AI skills — sometimes called tools, functions, or plugins — are rapidly becoming the core building blocks of agentic AI systems. They allow language models to retrieve data, perform specialized reasoning tasks, and execute automated workflows. But this capability also introduces a new layer of attack surface that many organizations are only beginning to understand. Research examining large ecosystems of agent skills has already found that over a quarter contain at least one security vulnerability, including prompt injection vectors, privilege escalation opportunities, and data-exfiltration risks.

The new database aims to make this emerging attack surface visible.

Each skill entry includes a structured security analysis designed to help practitioners understand how a capability might be abused inside real agent deployments. The assessment process uses a multi-dimensional security methodology combining automated scanning, specialized AI models trained to analyze agent behavior, and manual security review.

Rather than simply flagging potentially dangerous code patterns, the analysis follows a practical philosophy: instructions and behaviors are evaluated within the context of the skill’s intended purpose. This allows the review process to distinguish between normal operational capabilities and behaviors that could realistically be exploited by attackers manipulating an AI agent’s reasoning process.

The project reflects a broader shift occurring in AI system security. As AI agents move beyond text generation into task execution and autonomous workflows, the security boundary is increasingly defined by the capabilities those agents can invoke.

In this model, skills effectively become the execution layer of AI systems, capable of: • influencing agent decision-making • injecting context into reasoning processes • triggering automated actions • exposing data through tool outputs • interacting with other agents

Security researchers are beginning to recognize that these capabilities introduce attack patterns with few direct parallels in traditional software, including indirect prompt injection through retrieved content and confused-deputy attacks caused by agent tool invocation.

By cataloging and analyzing these capabilities, the database aims to provide security teams with a clearer understanding of how agent behavior translates into security risk.

The resource is publicly accessible and is expected to expand as the ecosystem of AI agent skills continues to grow.

The company behind the project, Tego AI, is currently operating in stealth mode while developing security technologies focused on the emerging agentic AI ecosystem.

joe-limia•1h ago
Despite the obvious self promotion, this whole concept of insecure skills is so dumb to me, if your engineers are installing and running random "skills" found online it's the same as if you had engineers copy and pasting commands into the terminal, it's superficial marketing bs at best
skybrian•12m ago
Installing npm modules seems similar as far as the risks go? The assumption is that you have a semi-trusted source of good libraries that's at least somewhat resistant to supply-chain attacks. A similar thing could in theory be done for well-known skills, but it requires a community norm of not releasing crap.

So it seems like the question is how do you build something worthy of people's trust?

Meta’s renewed commitment to jemalloc

https://engineering.fb.com/2026/03/02/data-infrastructure/investing-in-infrastructure-metas-renew...
213•hahahacorn•2h ago•85 comments

The “small web” is bigger than you might think

https://kevinboone.me/small_web_is_big.html
192•speckx•3h ago•64 comments

My Journey to a reliable and enjoyable locally hosted voice assistant (2025)

https://community.home-assistant.io/t/my-journey-to-a-reliable-and-enjoyable-locally-hosted-voice...
246•Vaslo•7h ago•83 comments

Language Model Teams as Distrbuted Systems

https://arxiv.org/abs/2603.12229
40•jryio•3h ago•8 comments

Why I love FreeBSD

https://it-notes.dragas.net/2026/03/16/why-i-love-freebsd/
267•enz•9h ago•107 comments

Launch HN: Voygr (YC W26) – A better maps API for agents and AI apps

48•ymarkov•4h ago•24 comments

Apideck CLI – An AI-agent interface with much lower context consumption than MCP

https://www.apideck.com/blog/mcp-server-eating-context-window-cli-alternative
94•gertjandewilde•5h ago•88 comments

Agent Skills – Open Security Database

https://index.tego.security/skills/
27•4ppsec•3h ago•4 comments

Nvidia Launches Vera CPU, Purpose-Built for Agentic AI

https://nvidianews.nvidia.com/news/nvidia-launches-vera-cpu-purpose-built-for-agentic-ai
33•lewismenelaws•46m ago•8 comments

Polymarket gamblers threaten to kill me over Iran missile story

https://www.timesofisrael.com/gamblers-trying-to-win-a-bet-on-polymarket-are-vowing-to-kill-me-if...
1080•defly•8h ago•706 comments

Cert Authorities Check for DNSSEC from Today

https://www.grepular.com/Cert_Authorities_Check_for_DNSSEC_From_Today
68•zdw•22h ago•121 comments

Starlink Mini as a failover

https://www.jackpearce.co.uk/posts/starlink-failover/
116•jkpe•12h ago•113 comments

Corruption erodes social trust more in democracies than in autocracies

https://www.frontiersin.org/journals/political-science/articles/10.3389/fpos.2026.1779810/full
590•PaulHoule•9h ago•302 comments

Kaizen (YC P25) Hiring Eng, GTM, Cos to Automate BPOs

https://www.kaizenautomation.com/careers
1•michaelssilver•3h ago

On The Need For Understanding

https://blog.information-superhighway.net/on-the-need-for-understanding
35•zdw•4d ago•8 comments

Launch HN: Chamber (YC W26) – An AI Teammate for GPU Infrastructure

https://www.usechamber.io/
17•jshen96•3h ago•4 comments

Lazycut: A simple terminal video trimmer using FFmpeg

https://github.com/emin-ozata/lazycut
117•masterpos•8h ago•40 comments

US Job Market Visualizer

https://karpathy.ai/jobs/
326•andygcook•5h ago•259 comments

Home Assistant waters my plants

https://finnian.io/blog/home-assistant-waters-my-plants/
213•finniananderson•4d ago•111 comments

MoD sources warn Palantir role at heart of government is threat to UK security

https://www.thenerve.news/p/palantir-technologies-uk-mod-sources-government-data-insights-securit...
506•vrganj•8h ago•201 comments

Lies I was told about collaborative editing, Part 2: Why we don't use Yjs

https://www.moment.dev/blog/lies-i-was-told-pt-2
153•antics•3d ago•86 comments

Kona EV Hacking

http://techno-fandom.org/~hobbit/cars/ev/
90•AnnikaL•4d ago•54 comments

Where does engineering go? Retreat findings and insights [pdf]

https://www.thoughtworks.com/content/dam/thoughtworks/documents/report/tw_future%20_of_software_d...
60•danebalia•5d ago•21 comments

AirPods Max 2

https://www.apple.com/airpods-max/
124•ssijak•7h ago•242 comments

The bureaucracy blocking the chance at a cure

https://www.writingruxandrabio.com/p/the-bureaucracy-blocking-the-chance
50•item•1d ago•77 comments

Show HN: Claude Code skills that build complete Godot games

https://github.com/htdt/godogen
34•htdt•4h ago•12 comments

Comparing Python Type Checkers: Typing Spec Conformance

https://pyrefly.org/blog/typing-conformance-comparison/
76•ocamoss•8h ago•23 comments

Speed at the cost of quality: Study of use of Cursor AI in open source projects

https://arxiv.org/abs/2511.04427
62•wek•3h ago•29 comments

Palestinian boy, 12, describes how Israeli forces killed his family in car

https://www.bbc.com/news/articles/c70n2x7p22do
489•tartoran•2h ago•128 comments

Even faster asin() was staring right at me

https://16bpp.net/blog/post/even-faster-asin-was-staring-right-at-me/
89•def-pri-pub•8h ago•42 comments