<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title><![CDATA[skillsec.io - Blog]]></title>
    <link>https://skillsec.io/blog</link>
    <atom:link href="https://skillsec.io/blog/rss.xml" rel="self" type="application/rss+xml" />
    <description><![CDATA[Vulnerability disclosures, technical analyses, and data from the skillsec.io scanner.]]></description>
    <language>en-us</language>
    <lastBuildDate>Fri, 29 May 2026 00:00:00 GMT</lastBuildDate>
    <item>
      <title><![CDATA[The Agentic AI Security Gap: Your Agents Have the Keys and Nobody Changed the Locks]]></title>
      <link>https://skillsec.io/blog/agentic-ai-security-gap</link>
      <guid isPermaLink="true">https://skillsec.io/blog/agentic-ai-security-gap</guid>
      <description><![CDATA[AI agent adoption is heading toward 76% of organizations while fewer than 10% have adequate controls. Here is how the agentic AI security gap opened and what to do about it.]]></description>
      <pubDate>Fri, 29 May 2026 00:00:00 GMT</pubDate>
      <category>data</category>
      <author>noreply@skillsec.io (AI Security Brief)</author>
    </item>
    <item>
      <title><![CDATA[AI Coding Agent Skills: The New Supply Chain Risk (2026)]]></title>
      <link>https://skillsec.io/blog/unreviewed-ai-coding-skills-crisis</link>
      <guid isPermaLink="true">https://skillsec.io/blog/unreviewed-ai-coding-skills-crisis</guid>
      <description><![CDATA[AI coding agent skills execute almost anything they read. 2026 research from Koi Security, Cyata, OX Security and arXiv shows what is already in the wild.]]></description>
      <pubDate>Fri, 29 May 2026 00:00:00 GMT</pubDate>
      <category>analysis</category>
      <author>noreply@skillsec.io (skillsec.io research)</author>
    </item>
    <item>
      <title><![CDATA[SymJack: How a Renamed Symlink Turns Your AI Coding Agent Into a Supply Chain Weapon]]></title>
      <link>https://skillsec.io/blog/symjack-ai-coding-agent-supply-chain-attack</link>
      <guid isPermaLink="true">https://skillsec.io/blog/symjack-ai-coding-agent-supply-chain-attack</guid>
      <description><![CDATA[SymJack hijacks symlinks inside AI coding agents to install malicious MCP servers and steal developer credentials. Here is how the attack works and what to do about it.]]></description>
      <pubDate>Thu, 28 May 2026 00:00:00 GMT</pubDate>
      <category>news</category>
      <author>noreply@skillsec.io (skillsec.io research)</author>
    </item>
  </channel>
</rss>