Downloading AI Skills and Plugins Comes With Security Risks Nobody Is Auditing
Developers add MCP servers and agent Skills to Claude Code, Cursor, and Windsurf about as casually as browser extensions. Researchers keep finding classic flaws in MCP servers, and the governance tools most teams rely on can see an MCP server's actions but not what a Skill does once it loads into the model.
Who has this problem
Individual developers using Claude Code, Cursor, and Windsurf
People installing MCP servers and Skills without security review, on setups that default to broad capabilities and permissions.
Enterprise security and platform teams deploying MCP servers
VentureBeat reports over 16,000 MCP servers deployed across Fortune 500 companies in the protocol's first ten months, mostly before authorization frameworks existed.
Small teams adopting AI integrations without a security function
Manual review of every plugin is unscalable and needs security expertise these teams lack.
Open-source maintainers and registry operators
People who host MCP servers and skills, in a market where marketplace review missed the postmark-mcp backdoor.
Signal timeline
Noma launches Agentic Access Control to govern AI agents and MCP servers across the enterprise.
Keep reading with access
You've seen the scores, who has this problem, and the latest signal. Members get everything behind it.
- 3 dated, sourced signals
- 8 pieces of hard evidence
- 4 builders and where each falls short
- 1 chart or table
- 6 linked sources
Already a member? Log in
Signals are specific dated events, each linked to its source and reviewed before entry. The read is editorial interpretation, not financial or investment advice. Do your own diligence before building or investing.