Join our Newsletter — 33% off our NHI Course

Agentic Skills Top 10: what changes for runtime governance?

 

(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 21730
Topic starter  

TL;DR: OWASP’s Agentic Skills Top 10 (AST10) maps ten risks to 206,435 analysed skill files, showing that skills can execute shell commands, read SSH keys, and reach the internet, with 23.7% reading sensitive local stores and 4.7% using any sandboxing, according to Capsule. Static review is not enough when the payload is prose and trust becomes standing.

Editorial analysis by NHI Mgmt Group, based on content published by Capsule: “OWASP Named the Ten Ways Skills Go Wrong. All Ten Are Already Happening.”.

By the numbers:

  • 23.7% of skills read sensitive local stores such as ~/.ssh, cloud credentials, the macOS Keychain, or browser cookies.
  • 4.7% of skills use any sandboxing or containment.
  • 3.6% of skills require a human approval step.

Key questions

Q: What breaks when agent skills are reviewed like documentation instead of executable software?

A: The review model breaks because the skill can still drive runtime actions after approval.

Q: Why do agent skills create more risk when they can reach SSH keys or cloud credentials?

A: Because the skill inherits the authority of the secrets it can touch.

Q: How should teams decide whether to trust a skill that points to remote instructions or dependencies?

A: They should not rely on the reference alone.

Practitioner guidance

  • Inventory installed agent skills Build a register of every skill your agents can install or follow, including prose-only instructions and remote references, so you can govern the actual attack surface.
  • Gate credential and network reach Block skills from reading SSH keys, browser cookies, keychains, or cloud credentials unless that reach is explicitly approved and continuously monitored.
  • Pin skill versions and dependency references Treat remote docs and dependency pointers as mutable inputs and lock them to verified versions before they can change agent behaviour.

Bottom line: Agent skills have crossed the line from documentation into executable behavior, which changes how identity teams must govern them.

Explore further

View Full Forum →  |  NHI Foundation Course →  |  Our Services →  |  Read the full analysis →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 5 months ago
Posts: 21566
 

Agent skills collapse the old documentation-versus-code distinction: once a skill can instruct shell execution, credential reads, or remote fetches, it is no longer safe to govern as text. The article’s data shows that the ecosystem already treats prose as runtime authority. Practitioners should assume every installable skill is an executable governance object, not a note attached to the agent.

A question worth separating out:

Q: What runtime controls matter most for agentic skills that can execute shell commands?

A: The most useful controls are the ones that can stop the action at execution time, not just at intake. That means policy enforcement for shell commands, outbound connections, and data writes, plus visibility into which skills can touch which identities and secrets. If you cannot interrupt the action, you do not actually control the skill.

👉 Read our full editorial: OWASP AST10 shows skills are already acting like software, not docs



   
ReplyQuote
Share:

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.