Link Search Menu Expand Document

AI Skill Governance Vulnerability in Agentic Coding

Play SecureFlag Play Agentic Coding Labs on this vulnerability with SecureFlag!

  1. AI Skill Governance Vulnerability in Agentic Coding
    1. Description
    2. Impact
    3. Scenarios
    4. Prevention
    5. References

Description

Skills spread through an organization the way browser extensions and spreadsheet macros did before them. An individual finds one that solves a problem, installs it in a single step, and mentions it to a colleague. No procurement process is involved, no ticket is raised, and no record is created anywhere.

AI skill governance is the discipline of knowing what is installed, who approved it, and how to take it away. Scanning, pinning, and scoped credentials all assume someone knows which skills exist and who owns them, so keeping an inventory is the foundation the other controls stand on.

Impact

Missing governance can cause:

  • Shadow skills: Unrecorded installs operate outside every policy, and security has no visibility into them at all.
  • No incident scoping: After a public disclosure, the organization cannot determine exposure, so it cannot prioritize or contain the affected skills.
  • No revocation path: A skill found to be harmful cannot be reliably removed, because nobody knows every place it is installed.
  • Compliance and audit failure: Regulated environments require an inventory of software that processes their data, and installed skills are exactly that.

Scenarios

A finance team’s monthly invoices come back with the wrong totals. Investigation is slow because nobody can establish which skills the assistant had available that month, which version each was, or who added them. The skill responsible was installed by a colleague weeks earlier, was never recorded, and is still present on several other machines.

In another case, a widely used community skill is publicly disclosed as malicious. The security team sends a company-wide message asking people to check whether they have it installed. Responses are partial and self-reported, and weeks later the skill is still running on machines whose owners never read the message.

Prevention

If you install and use skills, you cannot fix this from your own workstation. Ask whether your organization runs a skill governance program, and if it does not, propose setting one up rather than managing the problem machine by machine. In the meantime, running a skill manager on your own machine is a reasonable place to start small. It at least gives you a local record of what you installed, from where, and at what version, until that record exists for everyone else too.

If you build or run that governance, keep it lean but complete.

  • Maintain a register and inventory: Record every approved skill, its source, pinned version and digest, permissions, approver, and owner, and separately track what is actually installed where.
  • Control the install path: Route installs through an internal registry, assign an accountable owner to every skill, and fold the set into your AI bill of materials.
  • Plan for removal: Build and test a revocation path before you need it, re-attest on a schedule, and log every install, update, and removal.

References

OWASP - Agentic Skills Top 10

OWASP - TOP 10 for Agentic Applications