Agent skills package instructions, scripts, and resources that extend what an agent can do. Like browser extensions or open-source packages, they create a supply chain that attackers can target.
Skill poisoning vectors include:
OWASP launched an Agentic Skills Top 10 to address these risks, reflecting how quickly skill ecosystems have grown across coding and productivity agents.
Defenses include curated skill sources, review of skill contents before installation, signing and integrity checks, and runtime monitoring of what skills cause agents to do.
How PointGuard AI Helps
PointGuard AI Agentic Endpoint Security discovers installed skills, plugins, and MCP servers on managed devices and enforces policy on what agents may install. AI Runtime Guardrails inspect skill-driven instructions and actions at runtime.
Learn More
Our expert team can assess your needs, show you a live demo, and recommend a solution that will save you time and money.