Your AI agent trusts every skill it loads. Most people never read them. agentsec 0.4.0 now flags hidden prompt-injection & exfiltration instructions inside a skill's own text (OWASP AST05) — plus over-broad allowed-tools grants. npx agentsec 🛡️
2
54
Introducing AgentSec — security auditing for AI agent skills with built-in web3 support. OWASP AST10 covers generic skill risks. Our AST-10 Web3 Annex extends it with 12 onchain-specific rules: signing authority, Permit2 capture, blind signing, RPC pinning, kill-switch, MCP drift, oracle/slippage, key material. 🧵
3
1
13
91,777
We ran the full annex against 11 production DEX router agent skills: 🥇 @odosprotocol 88 B 🥈 SushiSwap 71 C 🥉 CowSwap 70 C Uniswap 49 D PancakeSwap 49 D KyberSwap 49 D Across 49 D deBridge 49 D 0x 48 D LI.FI 45 D 1inch 26 F
2
2
6
7,175