Image: tenable.com · rights & removal
Executive Summary
Security teams are increasingly using AI agents, which introduces expanded risk because these agents can act on credentials and interact with tools. To manage this risk, Tenable developed the Exchange Inspector to vet community-built AI agents before they are deployed in production environments. The vetting process involves three stages: automated screening using Tenable One AI Exposure to check for prompt injection and exposed secrets; frontier assessment using OpenAI GPT Cyber models to test for potential threats across various attack surfaces; and final human verification by security researchers who verify runtime behavior in a clean environment.
The CyberAgents Exchange serves as an open-source, vendor-agnostic directory for agentic AI components, covering areas like agent functionality, Model Context Protocol (MCP) servers, skills capture, and workflow playbooks. These components allow AI agents to perform complex tasks autonomously by planning steps and calling security tools, connecting them via MCP servers to existing security tooling. Vetted listings are driving efficiency gains for security teams, demonstrated by examples like SOC-Hunter reducing threat hunting time by 75% and the Splunk Tenable Cloud Security Skill accelerating investigation workflows.
Facts Only
* Exchange Inspector vetting requires three gates: automated check, frontier model assessment, and human verification.
* The automated screening uses Tenable One AI Exposure to flag prompt injection, exposed secrets, PII exposure, and sensitive data access.
* Frontier assessment utilizes OpenAI GPT Cyber models to theorize and test how agents could be abused regarding model reasoning, tool permissions, and chain actions.
* Human review validates automated and frontier findings by executing components in a clean environment to verify runtime behavior.
* The review tests 15 types of security issues across model, application, and infrastructure layers.
* Model layer issues include prompt injection, excessive agency, skill/playbook integrity, state/memory corruption, and user-intent failures.
* Application layer issues involve tool security, secrets handling, data exfiltration, output injection, and conventional flaws like injection and XSS.
* Infrastructure layer issues cover filesystem safety, code execution, network security (SSRF), supply chain risks, and denial of service.
* Vetted listings include SOC-Hunter, Splunk Tenable Cloud Security Skill, Remediation Priority & Impact Agent, and agentic workflow playbooks.
* SOC-Hunter reduced threat hunting time by 75% for the Tenable security team.
* The CyberAgents Exchange is an open-source directory for discovering, sharing, and deploying agentic AI.
Full Take
The mechanism of vetting community-driven AI agents by combining automated scanning, frontier model reasoning, and expert execution establishes a necessary friction point against the potential risk of deploying autonomous systems. The process shifts security assessment from static signature matching to dynamic, adversarial reasoning—testing not just what an agent *is*, but what it *could do* under manipulation. This directly addresses the supply chain vulnerability where trust is given by default to contributors.
The delineation of risks across the model, application, and infrastructure layers provides a crucial framework for understanding agentic security. The focus on agent-specific issues—like skill integrity and context management—suggests that traditional vulnerability scanning is insufficient when dealing with emergent properties of LLM orchestration. When agents are designed to automate complex decision-making (planning, tool calling), the failure modes shift from simple code bugs to systemic failures in autonomy, memory handling, and permission boundaries.
The success of the vetted listings demonstrates that rigorous, multi-stage review can yield quantifiable security efficiencies, moving beyond theoretical risk to practical operational improvements. However, the reliance on a small set of human experts for the final verification implies an inherent bottleneck. The critical tension lies between the need for community openness (the Exchange) and the necessity of enterprise-grade trust, mediated by the specific, costly process of the Inspector. This raises questions about whether future systems can embed more verifiable, automated reasoning checks without sacrificing the necessary depth provided by human expertise.
Bridge Questions: If the frontier models are only assessing what a threat actor *could* do, what mechanisms are needed to ensure that the verification stage consistently catches novel attack vectors that fall outside current known adversarial patterns? How should organizations balance the speed of agent deployment against the rigor demanded by this multi-stage vetting process when scaling agentic security adoption?
From the original · Tenable Blog
source AI agents Community-built AI agents, skills, and MCP servers are landing in SOC workflows fast. Here’s what the Exchange Inspector tests before a listing earns its vetted tag on the CyberAgents Exchange.Read the full story at tenable.com
Sentinel — Human
The text reads like high-level technical reporting or a product announcement, characterized by detailed feature explanations and structured argumentation common in industry press releases.
