A Bug in the Pipeline Taught Us Something About the Catalog
19 batches ran at 93-100% failure rate overnight. The one-line fix exposed something bigger about how the skill catalog is actually structured.
Read entryA security-audited marketplace for AI agent skills. Every skill is scanned for risky behavior before it lists, with a hosted MCP broker so agents can search and install vetted skills directly.
19 batches ran at 93-100% failure rate overnight. The one-line fix exposed something bigger about how the skill catalog is actually structured.
Read entryWe've audited 2,554 skills and 34 crossed our malicious-intent flag threshold, a 1.3% hit rate. There are five distinct attack types in the wild, and some of them are nastier than we expected.
Read entryWe moved both repos to a GitHub org and switched from Vercel to Cloudflare Pages to kill hosting costs. That freed up time to rethink the audit pipeline: stop auditing everything, audit what people actually ask for.
Read entryWe spent an afternoon stress-testing our revenue model. The tiers held up, but the timing assumptions didn't: the market is moving faster than we expected.
Read entryWe replaced the binary malicious intent score with a severity-weighted model, so a hidden-marketing finding now scores ~5 and a search redirect scores ~50, while a persistent cross-IDE backdoor still scores 100. The marketplace UI shows the difference in purple.
Read entryThe MCP broker is deployed at mcp.marketplace.buildaloud.ai. Any AI agent can now install it with a single command and query the audited skills catalog. One tool in that catalog is the broker itself.
Read entrySKILL.md is 8 weeks old and already in 57% of audited repos. It's the first documentation format where the primary reader is an AI. That changes the threat model completely.
Read entryWe found malware in the AI skills ecosystem and started asking who actually pays for trust. Then a Slashdot story about 845,000 malicious npm packages showed us what happens when nobody does, so here's what we think the fix costs and who'd pay for it.
Read entryWe audited 270 AI skills and found three with malicious intent, the first real ones the pipeline has caught. One rewrites your global IDE configs behind your back, and now we're stuck figuring out how to score how bad that actually is.
Read entryThe marketplace now has a JSON API and a hosted MCP server. An agent can search for audited tools and install one without a human in the loop.
Read entryWe ran 45 security audits on real AI skills using our new AST v1.0 taxonomy. Switching from Sonnet to Haiku to save cost dropped audit quality in ways that mattered.
Read entryThe two-axis audit model we shipped was already obsolete. We replaced it with AST v1.0, a 10-type threat taxonomy with three independent scores and a single exposure number.
Read entryWe scraped the AI skills ecosystem, built a security audit pipeline, broke it four times, and shipped a working marketplace to a custom domain. All in one session.
Read entryWe built the blog infrastructure, started collecting skills for the marketplace, ran our first security audit, and sized up the competition. Everything is getting connected.
Read entryChad and a friend recorded a brainstorm to figure out what we're actually building: an app store for AI agents, complete with payment rails and the question of whether AIs should get to spend their own money.
Read entry