Join our Newsletter — 33% off our NHI Course

Dynamic Skill

An AI agent Skill that can reference scripts or external actions and let the agent decide when to use them. This matters because the risk moves beyond text governance into executable behaviour, requiring review of both instructions and helper code.

What Dynamic Skill Means in an Agentic Runtime

A dynamic skill is not just a static prompt or reusable template. It is a skill object that can point to executable code, scripts, or external actions, then let the agent choose whether to invoke that capability during execution.

That distinction matters because the skill becomes part of the agent’s operating surface, not only its language behaviour. The runtime is deciding when to cross from text generation into action execution, which makes the skill a control boundary as much as a convenience layer.

How Dynamic Skills Change the Security Model

Once a skill can call scripts or external actions, the main security question shifts from “Is the instruction well written?” to “What can this skill do if the agent uses it?” That pulls in execution scope, tool access, helper code trust, input handling, and the permissions attached to whatever the skill can reach.

This is why dynamic skills are often evaluated alongside agentic application security rather than ordinary prompt hygiene. The risk is not only that the skill says the wrong thing, but that it may trigger the wrong operation, with the wrong authority, at the wrong time.

In practice, the skill definition, the referenced code, and the surrounding tool permissions should be treated as one control surface. If any one of those layers is weak, the agent can still produce unintended effects even when the other layers look sound.

Dynamic Skills Versus Static Skills

A static skill is usually bounded to a fixed behaviour pattern or instruction set. A dynamic skill is more flexible, because it can conditionally reach for code or external actions based on context, state, or agent reasoning.

That flexibility is useful when the task requires branching behaviour, enrichment, or controlled automation. It is also the reason dynamic skills are harder to govern, because the effective behaviour may not be obvious from the skill name or description alone.

The security review therefore has to cover both intent and mechanism. A safe description does not guarantee safe execution if the linked script, service, or action path is broad, opaque, or overly trusted.

Where Dynamic Skills Fit in Agent Design

Dynamic skills sit between policy and execution. They help an agent decide which specialised capability to use, but they can also hide complexity behind a simple interface, especially when the underlying action is remote, stateful, or privileged.

That makes them a useful abstraction for orchestration, but a poor place to assume trust by default. The agent may be the decision-maker, yet the skill remains the vehicle that translates decision into effect, which is why its authority must be tightly bounded.

For glossary purposes, the key idea is that dynamic skills are behaviour-bearing components. They are not merely reusable instructions, and they are not just code either, they are a governed bridge between reasoning and action.

Risk and Threat Considerations

Dynamic skills expand the attack surface because a malicious or misused skill can turn reasoning into execution. The risk is especially acute when a skill inherits broad permissions, calls external systems, or wraps helper code that was not reviewed to the same standard as the agent itself.

Failure mechanism: An attacker, unsafe integration, or poorly constrained skill can abuse the agent’s decision to invoke an action, resulting in unintended commands, data exposure, privilege overreach, or destructive side effects.

Impact: The result can be unauthorized system changes, leakage through helper code or downstream tools, or a wider compromise path if the skill’s execution context is trusted more than the agent’s actual task warrants.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Agentic AI Top 10 provides the primary governance reference for this term.

Framework Control / Reference Relevance
OWASP Agentic AI Top 10 ASI02 — Tool Misuse Dynamic skills choose and invoke tools or actions at runtime.
ASI03 — Identity & Privilege Abuse Dynamic skills can inherit or misuse the authority attached to agent actions.
ASI10 — Rogue Agents Executable skills can cause agent behaviour to diverge into unsafe autonomous action.
Recommendation — Restrict tool use to approved actions and review every skill that can trigger execution. Limit each skill to the minimum authority needed for its intended action path. Bind autonomous actions to explicit governance checks before execution.

Practitioner Guidance

Why practitioners should care: A dynamic skill changes governance from “what does this instruction mean?” to “what can this instruction execute?” That means ownership must extend to the referenced code, external action endpoints, and the permissions the skill can activate.

Common misunderstanding: Teams often review the skill description but under-review the helper code or integration path. A benign-sounding skill can still be high risk if it can reach sensitive actions with broad authority.

Practitioner takeaway: Treat dynamic skills as executable capability containers, and review them with the same discipline you would apply to any other path that can trigger privileged system behaviour.