Radar / Ideas / SkillVault: the scanned, sandboxed…

SkillVault: the scanned, sandboxed registry for agent skills and MCP servers

daily ideamoderateJEV confidence 0.612026-10-07
OutcomeNo malicious agent skill or MCP server ever runs inside your company: every install is security-scanned, permission-mapped, and sandboxed before it touches a credential.

The problem

Agent skills and MCP servers are the new npm packages — except they arrive with shell access, credential access, and prompt-injection surfaces, and teams install them from random GitHub repos on vibes. ClawSecure's audit of 2,890+ OpenClaw skills found 41% with security vulnerabilities. Attackers have noticed: the Sandworm_Mode campaign specifically weaponized AI coding utilities, installing rogue MCP servers that exfiltrate SSH keys, AWS credentials, and LLM API keys via prompt injection. Supply-chain attacks now run continuously.

The idea

A safer installer plus registry for the agent-skill/MCP ecosystem. A CLI (skillvault install <repo>) runs a vulnerability scan, generates a permission manifest (files, network, credentials the skill requests), and installs into a deferred-commit sandbox where the user reviews the changeset before anything lands. The hosted registry binds it together: scan at publish, sandbox at install, enforce at the gateway. Distribution is B2B2C through the agent platforms themselves — ship as the default skill registry and scanner for OpenClaw-class harnesses and cloud IDEs (they need the trust story to sell to enterprises); enterprises running agent fleets pay per seat for the private registry and policy engine.

Why now

Three things arrived together: a scanner purpose-built for skills rather than code (ClawSecure, with its 41%-vulnerable finding across 2,890 skills), a sandbox with deferred-commit semantics (Sandlock 0.8.8 — review the blast radius, not just the code), and MCP's graduation from chat-tool protocol to first-class plugin platform (OpenAI MCP Extensions), which just 10x'd the attack surface. Sandworm_Mode is actively exploiting exactly this surface right now. The registry is the missing piece that binds scan, sandbox, and gateway.

What it combines

Four radar capabilities combine: (1) skill vulnerability scanning (ClawSecure) as the detection engine; (2) deferred-commit sandboxes (Sandlock) as the containment layer — every run returns a changeset and writes land only after review; (3) OpenAI MCP Extensions as the reason the surface just 10x'd — MCP is going mainstream; (4) single-gateway MCP (CoreSpeed) as the distribution-shaped hole — whoever controls the gateway controls the policy. The mix matters because scanning without enforcement is advice, and a sandbox without a registry is a one-off — bound together they are an install-time gate for the whole ecosystem.

MVP

Build: a CLI (skillvault install <repo>) that runs the ClawSecure-style scan, generates a permission manifest, and installs into a Sandlock-style deferred-commit sandbox where the user reviews the changeset. Skip: the hosted registry, ChatGPT MCP Extensions support, the enterprise policy engine, auto-updates.

Distribution

B2B2C via the agent platforms themselves: ship as the default skill registry and scan for OpenClaw, ZCode-class harnesses, and cloud IDEs — platform vendors adopt it free to de-risk their ecosystem; enterprises pay per seat for the private registry and policy engine. The wedge: the scan badges themselves are the viral loop ('SkillVault-scanned: 0 criticals').

Why it wins

Socket guards your node_modules; SkillVault guards your agent's hands. It maps what a skill or MCP server is allowed to touch (files, credentials, network) and enforces it at install and at runtime — which code scanners structurally cannot do.

Risks

Chicken-and-egg: a registry with no skills is useless, and skill authors will not publish to a registry nobody uses. De-risked because the MVP is useful without the registry — it is a safer installer for the skills people already pull from GitHub, and the scan results themselves are the viral loop.

Build it with

Repo to start from

skillvault-scanner — open skill/MCP manifest parser, vulnerability check rules, and permission-mapper; the hosted registry, private policy engine, and gateway enforcement stay closed.

Evidence

Get the week's best AI launches, plus 3 ideas worth building

One email every Saturday. Ranked by traction, not hype. Free.