🚀NEW LABGetting Started with Claude AgentsStart lab
Agents · Safety

Skills as Verifiable Artifacts

First page
Skills as Verifiable Artifacts
Paper summary

If you ship agent skills, your runtime is treating signed-and-cleared skills as trusted by default. This paper argues a skill is untrusted code until it is verified, and the runtime should enforce that default rather than infer trust from origin. Without skill verification, HITL has to fire on every irreversible call, which degrades into rubber-stamping at any non-trivial scale. With verification as a separate gated process, HITL fires only for what is unverified. Skills are now first-class deployment artifacts, and we have decades of supply-chain lessons on what happens when trust is inferred from a signature. This is the right ask for SKILL.md before agent skill libraries become the next attack surface.

Ask this paper

Every Monday
Get next week’s papers.
Subscribe on Substack