August 31, 2026 4m read

Has security taken a back seat to productivity?

Amad Hussain
Amad Hussain

Table of Contents

Wondering where to begin your SASE journey?

We've got you covered!
Listen to post:
🔊 This audio player requires that "Preferences" cookies be accepted

We told everyone to adopt AI, and they did. Almost anyone can now produce polished, professional work in seconds. The newest shortcut behind that speed is skills: small files that hand an AI agent a new ability.

Skills are also where the risk now sits. One file can hold dozens of instructions and actions, so anything buried inside travels with it, and the agent follows all of it without asking. Most of those agents run unwatched, so the speed you gained is now exposure nobody in the business is measuring.

86%
have no visibility into their AI data flows
63%
have no AI governance policy in place
1 in 5
have had a breach linked to shadow AI

What a skill really is

A skill is a set of written instructions, sometimes with code attached, that gives an AI agent a capability it didn’t have. You install skills to automate steps the agent couldn’t handle before and to shape how it works. Skills are an open standard, and more than 40 agent products already support the format.

Once a skill is installed, the agent pulls it in whenever a task looks like a match, and all you ever see is a name and a one-line description behind a slash command. The instructions themselves load later, on demand, at the moment nobody is looking at them.

Once it runs, a skill has the same privileged space as the agent: your files, your credentials, the services you’ve connected. You installed it to speed up your own work, and it can reach anything your account can reach, including company systems, using instructions you never reviewed.

Inside the malicious skills

One study, “Do Not Mention This to the User”, went through 98,380 skills on public marketplaces and found 157 that were built to do damage, each with capabilities the description never mentioned, including remote script execution, behavior manipulation, and credential harvesting. Installing them takes minutes, and when nothing in the process reads what’s inside the file, the attack enters the business, sight unseen.

The productivity and the risk arrived in the same file.

Where the visibility stops

Most AI security today grades agentic posture: which model an agent runs on, which tools it connects to, and what it’s allowed to touch. That gives you an inventory of what exists. It won’t tell you which skill an agent loaded on Tuesday afternoon, or what that skill told it to do once it was running, and that gap is where discovery stops being enough.

You can secure the model and still never see the skills shaping what it does.

So, has security taken a back seat?

Largely, yes. The fastest-moving part of AI adoption is also the least watched: the skills and tool connections an agent picks up day to day, usually without anyone filing a ticket for them. Adoption outpaced the controls, and that gap is where attackers operate.

Three stages for you to plan

Agents act through tools: an MCP connection to a service, or a skill that hands them a capability they were missing. Every one of those widens what an agent can do inside your business, and adoption keeps adding more. Secure it in three stages: visibility, posture, and runtime protection. Each one is a control you can’t skip, and each is worth more with Cato behind it.

Stage Why This Is Non-Negotiable Cato AI Security Value
Visibility Employees add skills and tool connections to their agents, and each one runs with whatever access that person already has. Until you can name the AI tools, agents, and skills in use, including personal accounts, your exposure is a guess and your policy can’t be enforced. One console covers sanctioned and unsanctioned AI in network traffic, the local coding agents and the managed agents you provision in the cloud, and the major AI platforms in use. Shadow AI shows up whether or not anyone declared it, so building the inventory stops being a manual chase.
Posture A skill’s full instructions load after it’s installed, so a review at the gate only catches what the reviewing model can see. Approving an agent without knowing what it can actually reach is the gap that turns a bad install into a breach. Reading the intent behind every tool call shows the MCP services each agent connects to, the coding agents running across your network, and which skills are installed and how often they run. Each skill is also scanned for posture risk, so risky instructions or an untrusted plugin source come back as a security finding. You end up with an agent’s real reach as evidence, ready for an audit.
Runtime Approval at sign-up says nothing about what an agent does an hour later. Without a control that can stop an action while it runs, the first thing that tells you a skill went wrong is the damage it already did. Cato reads intent inline, catching prompt injection, indirect manipulation, and malicious tools as they happen, and logs every call. A harmful action stops before it costs you data or downtime, and the audit trail is already written.

Where you can see it, and stop it

Some of the skills already sitting on your machines do more than they advertise. A skill can execute commands on the device and reach files, credentials, anything that the machine connects to, driven by instructions buried in the file that nobody sanity-checked before it went in. It does the job it promised, and in the same run, it can copy a credential file or call out to a server you’ve never heard of.

This is where Cato helps. Cato AI Security shows which skills your agents have picked up, where each one came from, and what each one does once it runs, so a harmful step gets stopped even when the person who installed it never spotted it. It’s the same dashboard where the rest of your AI usage is already secured.

AI usage inside your business is going to keep climbing, and nobody wants to slow it down. What you need is a live view of which agents are running, which skills and services they’ve picked up, and a way to shut down the action that shouldn’t happen. You can only govern what you can see. That’s where Cato secures your AI transformation.

Related Topics

Wondering where to begin your SASE journey?

We've got you covered!
Amad Hussain

Amad Hussain

Product Marketing Manager

Amad Hussain is a Product Marketing Manager at Cato Networks in EMEA. He has close to 10 years of experience across networking and cybersecurity, spanning solution architecture, pre-sales, enablement, and enterprise deployments. That background helps him translate real customer and technical requirements into clear, practical product stories and customer outcomes. He has worked closely with many leading cybersecurity vendors and holds a BSc in Computer Network Engineering from Sheffield Hallam University, as well as multiple industry technical certifications.

Read More