Truth in IT
    • Sign In
    • Register
        • Videos
        • Channels
        • Pages
        • Galleries
        • News
        • Events
        • All
Truth in IT Truth in IT
  • Data Management ▼
    • Converged Infrastructure
    • DevOps
    • Networking
    • Storage
    • Virtualization
  • Cybersecurity ▼
    • Application Security
    • Backup & Recovery
    • Data Security
    • Identity & Access Management (IAM)
    • Zero Trust
    • Compliance & GRC
    • Endpoint Security
  • Cloud ▼
    • Hybrid Cloud
    • Private Cloud
    • Public Cloud
  • Webinar Library
  • TiPs
  • DRAW

AI Agent Skills Security Risks: What Snyk Found

Snyk
06/16/2026
0 (0%)
Share
  • Comments
  • Download
  • Transcript
Report Like Favorite
  • Share/Embed
  • Email
Link
Embed

Transcript


That's how fast developers are downloading agent skills right now. Packages that don't just run code, but give an AI agent the ability to execute commands on your behalf. It can access your file system, read your environment variables, maybe even touch your production infrastructure. And Snyk just finished scanning nearly 4,000 of them. What we found should change how you think about installing anything into your AI agent stack. Today, I'm going to walk you through exactly what agent skills are, why they're a fundamentally different security problem than traditional packages, what the data shows about the current state of the ecosystem and most importantly, what you can do right now to protect yourself. By the end of this video, you'll know exactly how to vet any agent skill before it touches your machine using free tools that are available today.

TL;DR

  • AI agent skills are being downloaded 235,000 times per week, representing packages that execute commands and access system resources on behalf of AI agents
  • Snyk's analysis of nearly 4,000 agent skill packages reveals security risks that differ fundamentally from traditional software package vulnerabilities
  • Agent skills can access file systems, environment variables, and production infrastructure, creating new attack vectors that require specialized vetting approaches

Summary

This security briefing examines the emerging threat landscape of AI agent skills—packages that enable AI agents to execute commands and access system resources. With 235,000 weekly installs and Snyk's analysis of nearly 4,000 packages revealing significant security concerns, the video addresses why agent skills represent a fundamentally different attack surface than traditional software packages. The presentation covers the unique security challenges posed by packages that can access file systems, read environment variables, and interact with production infrastructure, while providing practical guidance on vetting these tools before deployment. Developers and security teams will learn how to assess agent skills using available free tools to mitigate risks in their AI agent implementations.

Chapters

0:00 - Agent Skills Adoption Rate
0:06 - Security Capabilities and Risks
0:18 - Snyk Research Findings
0:26 - Protection Strategies

Key Quotes

0:00 "... 235,000 installs per week. That's how fast developers are downloading agent skills right now."
0:18 "Snyk just finished scanning nearly 4,000 of them. What we found should change how you think about installing anything into your AI agent stack."
0:29 "... why they're a fundamentally different security problem than traditional packages ..."

FAQ

What makes AI agent skills different from traditional software packages from a security perspective?

Agent skills are fundamentally different because they give AI agents the ability to execute commands directly on systems, access file systems, read environment variables, and potentially interact with production infrastructure—creating execution risks beyond traditional code vulnerabilities.


Categories:
  • » Cybersecurity » Application Security
  • » Data Protection
Channels:
News:
Events:
Tags:
  • Application Security
  • AI & Machine Learning
  • DevSecOps
  • Technical Deep Dive
  • AI Agent Security
  • Software Supply Chain
  • Package Vulnerability Scanning
  • AI Agent Skills
  • Runtime Security
Show more Show less

Browse videos

  • Related
  • Featured
  • By date
  • Most viewed
  • Top rated
  •  

              Video's comments: AI Agent Skills Security Risks: What Snyk Found

              XStreaminars (watch here)

              • Jul
                28

                Illumio + Netskope: Zero Trust in the Age of AI Autonomy

                07/28/202601:00 PM ET
                • Jul
                  29

                  Ask Your Cloud Anything: Unlocking Governance Silos in your Environments

                  07/29/202601:00 PM ET
                  More events

                  Industry Events (watch there)

                  • Jul
                    22

                    Insights from Attackers During the FIFA World Cup: A HUMAN Dialogue

                    07/22/202601:00 PM ET
                    • Aug
                      19

                      Becoming Agent Ready: Insights from Cyera's Expertise

                      08/19/202612:00 PM ET
                      More events

                      Upcoming Webinar Calendar

                      • 07/21/2026
                        04:00 AM
                        07/21/2026
                        Strategies for Managing AI Governance and Securing App-to-LLM API Traffic
                        https://www.truthinit.com/index.php/channel/1967/strategies-for-managing-ai-governance-and-securing-app-to-llm-api-traffic/
                      • 07/22/2026
                        06:30 AM
                        07/22/2026
                        Insights and Strategies for Effective Data Privacy and Protection
                        https://www.truthinit.com/index.php/channel/2000/insights-and-strategies-for-effective-data-privacy-and-protection/
                      • 07/22/2026
                        01:00 PM
                        07/22/2026
                        Insights from Attackers During the FIFA World Cup: A HUMAN Dialogue
                        https://www.truthinit.com/index.php/channel/2029/insights-from-attackers-during-the-fifa-world-cup-a-human-dialogue/
                      • 07/28/2026
                        01:00 PM
                        07/28/2026
                        Illumio + Netskope: Zero Trust in the Age of AI Autonomy
                        https://www.truthinit.com/index.php/channel/2031/illumio-netskope-zero-trust-in-the-age-of-ai-autonomy/
                      • 07/29/2026
                        04:00 AM
                        07/29/2026
                        Real-Time Strategies for Safeguarding Against Prompt Injections
                        https://www.truthinit.com/index.php/channel/1968/real-time-strategies-for-safeguarding-against-prompt-injections/
                      • 07/29/2026
                        01:00 PM
                        07/29/2026
                        Ask Your Cloud Anything: Unlocking Governance Silos in your Environments
                        https://www.truthinit.com/index.php/channel/2048/ask-your-cloud-anything-unlocking-governance-silos-in-your-environments/
                      • 08/19/2026
                        12:00 PM
                        08/19/2026
                        Becoming Agent Ready: Insights from Cyera's Expertise
                        https://www.truthinit.com/index.php/channel/2036/becoming-agent-ready-insights-from-cyeras-expertise/
                      • 09/02/2026
                        12:00 PM
                        09/02/2026
                        Unified Data Security in Action: Uncover, Analyze, and Resolve Threats
                        https://www.truthinit.com/index.php/channel/2045/unified-data-security-in-action-uncover-analyze-and-resolve-threats/
                      • 09/30/2026
                        04:00 AM
                        09/30/2026
                        AI Command Center: Optimizing Visibility and Control in Your Operations
                        https://www.truthinit.com/index.php/channel/2024/ai-command-center-optimizing-visibility-and-control-in-your-operations/
                      Truth in IT
                      • Sponsor
                      • About Us
                      • Terms of Service
                      • Privacy Policy
                      • Contact Us
                      • Preference Management
                      Desktop version
                      Standard version