Skills are the new attack surface
Your employees and agents install skills from public marketplaces with zero gatekeeping. A single malicious SKILL.md inherits the full permissions of the agent it extends - your filesystem, your API keys, your internal systems.

36%
of public skills contain prompt injection vulnerabilities.
6.3
average security issues found per skill in marketplace audits.
26K+
agents hit by the AIR "brand-landingpage" fake skill campaign.
Frequently asked questions
How does Akto discover skills across my environment?
What types of threats does Akto detect in skill files?
Can I block a skill on specific devices without affecting the rest of my org?
How do runtime guardrails work alongside skill scanning?
Does Akto cover the OWASP Agentic Skills Top 10?


