AgentsAgent Skills Supply Chain Triple Defense — Snyk + Gen + Socket on skills.shSnyk Blog·high signalXBlueskyLinkedInCopy linkVercel skills.sh (69K+ skills) now has triple-layer security: Snyk (36% prompt injection rate), Gen Agent Trust Hub (4-tier risk), Socket (94.5% precision).SourceSource pageSnyk Blog↳ Follow the threadShared entity / Threat patternVercel Connect Goes GA: Deployments Swap Long-Lived Provider Secrets for OIDC-Scoped Short-Lived TokensVercel ChangelogPolicy dependency / Stack layerAttnlocate treats prompt injection as an object detection problem inside the attention matrix, hitting 0.934 TPR at 0.067 FPRarXivPolicy dependency / Stack layerWebMCP-Phalanx blocks all 80 tool-description injections in a browser agent, then gets bypassed by a malicious tool name called before inspectionarXivStack layer / Threat patternClaude Code ships /claude-api cost-optimize, a skill that profiles an existing project's API spend one measured change at a timeClaude Code changelogStack layer / Threat patternGitHub cut secret-scanning false positives 95% and published the eval methodology behind itGitHub BlogStack layer / Threat patternA single linear direction in the residual stream dials an agent's tool-call rate from ~0% to over 90% without retraining or prompt changesarXiv 2608.25198Stack layer / Threat patternClaude Code 2.1.247 Stops Subagents From Dying on a First-Call Model 404Claude Code ChangelogStack layer / Threat patternJensen Huang: 'compute is revenue', and an agent needs 15 to 100 times the compute of a human using the same modelCNBC