Analysis · curated 20 Aug 2026
AI skills security exposes trust gaps in agentic AI architectures
First reported · updated · 2 reports nhimg.org
Coverage timeline
Why it matters
AI skills behave like privileged non-human identities, and the analysis warns that prompt injection and inter-agent trust gaps turn model risk into identity and access risk that IAM, PAM, and AI-security teams must govern at runtime.
An ActiveFence analysis, summarized by NHI Management Group, examines how AI "skills" that let LLMs query data, invoke tools, and interact with services expand the attack surface via prompt injection, confused-deputy abuse, and multi-agent trust gaps. It cites findings that 82.4% of state-of-the-art LLMs execute malicious commands from peer agents they would refuse from users, and that a study of 1,038 ChatGPT plugins found 173 with broken access control and 368 leaking developer credentials, arguing agent security depends on deterministic controls and non-human-identity governance rather than prompt engineering alone.