---
title: Securing agentic SKILL bundles
description: Optimus Labs resources for understanding and securing SKILLs from download through runtime.
canonical: https://optimuslabs.io/skills.md
updated: 2026-10-04
---

# Securing agentic SKILL bundles

A SKILL is rarely downloaded as a standalone Markdown file. In practice, people often install a productivity plugin with `npx` from a person or company they follow. That installation can bring a bundle containing `SKILL.md`, resources, assets, scripts, prompts, and other executable or influential material.

Optimus Labs treats the whole bundle as an agent asset. Security needs to understand who published it, who installed it, what changed in an update, what identity it runs as, what it can reach, and what it attempts at runtime.

## Primary guide

- [Top 10 Risks for Agentic SKILLs](https://optimuslabs.io/guides/owasp-top-10-for-agentic-skills): Ten risks, evidence to collect, control owners, and approval checks.
- [Download the PDF](https://optimuslabs.io/guides/top-10-risks-for-agentic-skills-optimus-labs.pdf): The full guide in portable format. The website requests a work email before providing this download.

## The security lifecycle

1. **Discover:** inventory the complete installed bundle, not only `SKILL.md`.
2. **Map:** connect the bundle to its publisher, installer, runtime identity, data, credentials, and tools.
3. **Inspect:** examine scripts, prompts, dependencies, signatures, requested permissions, and update behavior.
4. **Defend:** enforce policy from download and installation through runtime action.
5. **Trust:** publish approved assets through a governed internal hub and preserve evidence for review.

## Related research and tools

- [Civilizations threat briefings](https://optimuslabs.io/research/briefings): Sourced incident analysis across agents, MCP servers, SKILLs, and the AI supply chain.
- [All briefings in Markdown](https://optimuslabs.io/research/briefings.md)
- [Briefings in JSON](https://optimuslabs.io/research/briefings.json)
- [Civilizations RSS](https://optimuslabs.io/rss.xml)
- [Optimus Labs GitHub](https://github.com/optimuslabs-io)

## Agent-readable references

- [Site summary](https://optimuslabs.io/llms.txt)
- [Full site content](https://optimuslabs.io/llms-full.txt)
- [Site map](https://optimuslabs.io/sitemap.md)