Product Announcements

Forum Discussion

nickh10's avatar
nickh10
Product Team
2 days ago

Exchange Inspector Is Now Live on the CyberAgents Exchange

“Is it safe to run?” That’s the question that can give security teams pause after they find a promising open source AI agent. Starting today, the CyberAgents Exchange AI Inspector (aka, “Exchange Inspector”) answers that.

With the Exchange Inspector, select community-built AI agents, skills, MCP servers, and playbooks on the Exchange now carry the Exchange Inspector vetted tag — the highest level of security review a listing can receive. We built it through Tenable’s participation in the OpenAI Daybreak Defense Network, and it’s the first major release from that collaboration.

To earn the tag, a listing has to clear three stages of enterprise-grade review:

  • Stage 1: Automated screening with Tenable One AI Exposure. The skills-inspection engine parses the agent’s instructions, the tools it can invoke, and the data it can reach, then flags prompt injection, hidden instructions, hardcoded secrets, and risky data access.
  • Stage 2: Frontier assessment by OpenAI GPT Cyber models. The models reason through the code and its threat model to surface novel attack techniques that signature-based checks miss.
  • Stage 3: Hands-on verification by Tenable security researchers. Our team installs and runs the listing in a clean environment to confirm how it actually behaves, not just how it’s documented.

Across those three stages, the review tests 15 types of security issues at three layers of the stack, from conventional flaws like SSRF and path traversal to agent-specific ones like excessive permissions and memory poisoning.

Three listings already carry the Exchange Inspector vetted tag:

Check out all of the open source AI security agents on the CyberAgents Exchange. Everything stays free and open source; no fees to list or use anything on it.

Learn More

No RepliesBe the first to reply