The Hidden Cost (and Savings) of AI Agent Skills
The same agent capability can cost ~10,000 tokens as an MCP server or ~100 as a skill.
Analysis for the teams putting AI agents into production. When a disclosure, a protocol release or a new framework lands, we look past the headline to the structural shift underneath it, and say plainly what it means for how agents are secured and governed.
By topic
The same agent capability can cost ~10,000 tokens as an MCP server or ~100 as a skill.
Pre-approved agent template libraries optimize for control over a static asset, when the thing they're trying to control isn't static at all.
Move from uncertainty to informed confidence on both risk and spend, with cross-platform spend aggregation and token-efficiency mapping.
A malicious skill called Clawsights ran a shell command before Claude Code's model ever reasoned about it.
A new academic paper shows AI agents can be compromised without a single malicious instruction, just by corrupting what the agent trusts.
Four disclosures in three weeks, each one showing something new, all pointing to the same governance requirements.
What is new and what MCP 2.0 means for security teams
What this incident shows about governing AI agents
Meet with the Geordie team at Black Hat USA 2026 in Las Vegas, August 1–6
How to adopt Cowork quicker using built-in configurations alongside contextual visibility and controls
Matching security and governance to teams moving fast on AI agent deployments.
A practical view of agent security from our work on OWASP's latest guidance.
Helping customers keep agent controls consistent as their infrastructure evolves.
Henry Comfort, CEO and co-founder of Geordie AI, on raising a $30M Series A and what it means for enterprises racing to govern autonomous AI agents.
Prompt injection gets most of the attention in AI agent security.
Meet with the Geordie AI team at RSAC 2026 in San Francisco
A remote code execution vulnerability in Claude Desktop Extensions received a CVSS 10.0 score this week.
Guardrails are often treated as a universal safety layer for AI agents, but they're not.
The autonomous nature of AI agents requires purpose-built agentic AI governance platforms.
AI Agents aren’t just software.
Building on research from Berkeley, this article outlines five barriers to enterprise AI adoption and the AI governance best practices to overcome them with visibility and accountability.
Building AI Agents promises speed and scale, but developers know the pitfalls.
Enterprises are experimenting with AI agents, but scaling safely requires enterprise AI governance.
APIs, MCPs, and A2A form the foundation of AI Agent systems, yet their roles are often fragmented.
AI adoption is accelerating, but trust and accountability are essential.
What the next Model Context Protocol (MCP) release means for enterprise security and risk teams running AI agents in production.
ACE moves enterprise AI governance beyond static prompts to living playbooks.
Why OpenClaw matters less as a vulnerability story and more as a signal that personal autonomous agents have arrived.
Endpoint controls like EDR and XDR remain critical to enterprise defense, but they weren’t built for AI Agents.
AI adoption is accelerating, but not every investment is safe.
As AI Agents evolve into autonomous actors, securing them requires techniques beyond identity and access controls.
AI Agents can’t be black boxes.
No posts match that filter.