4 min read
SKILL.md Is the New package.json — Treat Your Skill Library Like the Supply Chain It Is
Agent skills are unsigned, executable third-party code — a supply chain most teams install on vibes. How to govern your skill library like one.
2 posts tagged with “safe autonomy”
Agent skills are unsigned, executable third-party code — a supply chain most teams install on vibes. How to govern your skill library like one.
Anthropic just open-sourced its AI "defender's loop." The real lesson isn't about C code — it's that the bottleneck moved from finding vulnerabilities to trusting what your agents tell you, and that's a governance problem you own.