InfoNews
StepSecurity Now Inventories AI Agent Skills in Your GitHub Repositories and on Developer Machines
- Published
- Record updated
Summary
StepSecurity now gives security teams an inventory of AI agent skills on developer machines and in GitHub repositories. Dev Machine Guard scans supported locations on developer devices, including ~/.agents/skills, agent-specific directories such as ~/.claude/skills, project-level skill folders, the skills.sh lock file, and skills supplied by installed Claude Code and Codex plugins. A new Agent Skills page under GitHub shows skills committed to an organization's repositories on GitHub.com.
Topics
Related items
- LowCVE-2026-107288: Pydantic AI web fetch bypasses blocked_domains via hostname variantsSimilar attack · NVD/CVE Database
- LowOAuth grants pile up faster than you can review them. Here's how to keep up.Similar attack · BleepingComputer
- MediumTop MCP security resources — October 2026Similar attack · Adversa AI Blog
- MediumTensorLake npm SDK Compromised in ChainDrop Shai-Hulud Credential-Stealing AttackSimilar attack · Socket Blog
- MediumPoeLLM Malware Infects 3,400+ Servers to Expand Crypto Mining BotnetSimilar attack · The Hacker News