← Tech
CrowdedTech · Worklast signal Jun 2026

Downloading AI Skills and Plugins Comes With Security Risks Nobody Is Auditing

Developers add MCP servers and agent Skills to Claude Code, Cursor, and Windsurf about as casually as browser extensions. Researchers keep finding classic flaws in MCP servers, and the governance tools most teams rely on can see an MCP server's actions but not what a Skill does once it loads into the model.

Opportunity
7Strong
Pain
7High Pain
Feasibility
6Challenging
Timing
9Perfect Timing

Individual developers using Claude Code, Cursor, and Windsurf

People installing MCP servers and Skills without security review, on setups that default to broad capabilities and permissions.

Enterprise security and platform teams deploying MCP servers

VentureBeat reports over 16,000 MCP servers deployed across Fortune 500 companies in the protocol's first ten months, mostly before authorization frameworks existed.

Small teams adopting AI integrations without a security function

Manual review of every plugin is unscalable and needs security expertise these teams lack.

Open-source maintainers and registry operators

People who host MCP servers and skills, in a market where marketplace review missed the postmark-mcp backdoor.

Signal timeline

Jun 2026latest
Competitor

Noma launches Agentic Access Control to govern AI agents and MCP servers across the enterprise.

Help Net Security / Noma Security
Free preview

Keep reading with access

You've seen the scores, who has this problem, and the latest signal. Members get everything behind it.

Get access ↗

Signals are specific dated events, each linked to its source and reviewed before entry. The read is editorial interpretation, not financial or investment advice. Do your own diligence before building or investing.