Engineering brief
Nubank's Playbook for AI Supply Chain Security That Most Teams Lack
At a glance
- Relevance
- Practical value
- Warnings
- None
Nubank scanned 2,000 AI skills and found 1,500+ risks. Their lesson: treat skill configurations like library dependencies.
AI skills are the new supply chain. Most teams ignore their security risks.
Summary
Nubank’s product security manager reveals a systemic gap: AI skills—configuration files that guide agent behavior—behave like supply chain dependencies but lack traditional security vetting. After scanning 2,000 skills internally, they found over 1,500 risks, including credential leaks, destructive shell commands, and excessive permissions. The scale is non-trivial.
Teams likely treat AI skills as harmless plugins. That assumption is dangerous. Nubank built Skill Vector, a hybrid CI scanner using deterministic regex and LLM reviews, to catch unsafe instructions before skills reach the internal marketplace. The system blocked critical risks and forced remediation on hundreds of others.
The tradeoff is governance velocity. Local iteration is allowed, but CI gating creates friction. Developers want speed; security demands safety. Nubank’s solution—scanning locally, in PRs, and post-upload—balances both, but only for a single marketplace. External skill sources remain unvetted.
Engineering leaders should watch for this pattern. Skills, MCP servers, and agent rules are the new attack surface. Most organizations lack equivalent review pipelines. The lesson is clear: you must inspect the configuration layer, not just the generated code, or risk silent supply chain contamination.
Watch the video
This video is blocked due to your privacy settings. To watch this video, please accept YouTube marketing cookies.
Related breakdowns
AI slop is measurable—and fixing it requires judgment, not just bigger models
AI output collapses to the mean. Taste Labs shows slop is measurable with simple probes, and that brand APIs can dramatically improve fit. The real fix is at…
Why AI Can’t One-Shot Design and What That Means for Your Team
AI can’t one-shot good design. Paul Bakaus explains why adjectives and verbs are the missing control layer for steering AI design output—and what that means…
ACP: The protocol that could finally decouple clients from agent harnesses
ACP standardizes how clients talk to AI agents. Early demos show any client controlling any harness. Adoption is the open question.
Get TL;DW
Too Long; Didn't Watch.
A concise breakdowns of the AI and devtools videos that actually matter for engineering leaders.
Free. Weekly. No hype.
Video and thumbnails remain the property of their respective creators. tldw.news provides editorial analysis, commentary, and discovery links to original content.