ResearchSkillFortify supply chain verificationWweb·medium signalXBlueskyLinkedInCopy linkFormal verification for AI skill supply chains. 540 skills scanned, 96.95% F1, 100% precision, 0% FP. Processes 1000-node graphs in <100ms. References ClawHavoc campaign (1200+ malicious skills). arXiv 2603.00195↳ Follow the threadStack layer / Threat patternCROSS-CATEGORY: The Guardrail Layer Around Coding Agents Shipped at Four Different Points in the Lifecycle in 48 HoursHacker News Show HN and Product Hunt (2026-08-24 and 2026-08-25)Policy dependency / Stack layerCherry Studio v2.0.9 unifies tool approval into one declarative policy and lets the provider catalog hot-update without an app releaseGitHubPolicy dependency / Stack layerAttnlocate treats prompt injection as an object detection problem inside the attention matrix, hitting 0.934 TPR at 0.067 FPRarXivStack layer / Threat patternSkillPreflight Publishes a 100-Point Scorecard for Agent Skills and a Benchmark of 40 Public OnesGitHub (via Show HN, 2026-08-25)Stack layer / ContrastMicrosoft's Agent Lightning v1.0.1 ships an agent skill whose job is optimizing other agents, installed through gh skillGitHubStack layer / Threat patternSecurity-Oriented Prompts Redistribute Rather Than Reduce Vulnerabilities in LLM-Generated Python, and Silently Rewrite Requested CodearXiv 2608.24857Policy dependency / Stack layerWebMCP-Phalanx blocks all 80 tool-description injections in a browser agent, then gets bypassed by a malicious tool name called before inspectionarXivStack layer / Threat patternQWED-MCP, a Verification Gateway, Passed Attacker Math Straight to SymPy parse_expr (CVE-2026-55546, 9.8)GitHub Security Advisories