cybersecurity analyst security operations center

Tenable Holdings (Nasdaq: TENB) has expanded its CyberAgents Exchange with an AI Inspector designed to evaluate selected open-source AI agents, skills and Model Context Protocol servers before organizations deploy them. The company said the new component combines automated inspection, an assessment using OpenAI’s GPT cyber models and review by Tenable security researchers.

The CyberAgents Exchange is an open-source hub where security professionals can discover and share components built for cybersecurity work. Its new inspection process is intended to provide an additional security review for items listed on the exchange, a useful capability as organizations begin to connect AI agents to data sources, tools and security workflows.

Tenable said the first phase uses the skills-inspection engine in its Tenable One AI Exposure product. That engine is designed to find malicious content, prompt-injection attempts and the exposure of hardcoded secrets or customer data. A second phase applies a frontier-model assessment, followed by a human review from the company’s security research team.

That multi-stage approach reflects a basic challenge in agent deployment: the code or instructions an agent uses can create risk even when the underlying language model is trustworthy. An agent may include an unsafe tool call, expose credentials in a configuration file or be vulnerable to adversarial instructions. Automated screening can help locate those risks, but it is not a substitute for an organization’s own review of permissions, data flows and production controls.

Tenable said it will select components for inspection that have demonstrated measurable results. The initial examples include a threat-hunting skill, a vulnerability-remediation prioritization agent and a cloud-security-querying skill. The company reported time-savings estimates for those components, but did not publish independent validation of the figures or a comprehensive list of the criteria needed for a component to receive inspection.

Operationally, the inspection result needs to become one input to a repeatable intake process. A security team could use it to decide whether a component can enter a sandbox, which permissions it may receive and whether it needs additional code review. Without that follow-through, an assessment result alone will not prevent a risky integration from reaching production.

The company also leaves several deployment questions unanswered. It does not specify how often a reviewed component will be re-evaluated after its code, prompts or dependencies change; whether reviews apply to every version; or how an enterprise can combine the exchange’s evaluation with its own software-supply-chain and approval processes.

Those questions matter because an AI component that is safe in a test environment can still introduce risk when it receives broad access to incident records, cloud data or production tools. Security teams need to treat agent code, prompts, connectors and MCP servers as managed software components, with identity boundaries, version control, logging and a way to revoke access.

For enterprise security teams, the material change is a structured review layer that can provide more context before a community-built agent or skill moves into a live environment. Tenable’s approach does not certify an agent as safe, and it does not remove the need for customer controls. It can, however, add another screening step to an emerging part of the security toolchain where adoption has begun to outpace established governance practices.

Leave a Reply

Your email address will not be published. Required fields are marked *

Latest News