We Vetted 2000 AI Skills Before They Reached Developers — Lucas Palma, Nubank
Nubank built a security review system to vet 2,000 AI skills as supply chain dependencies
“although they look like configuration they behave like supply chain dependence like uh for example libraries and others”
Nubank's product security team treated AI skills, plugins, and MCP servers as supply chain attack vectors rather than mere configuration, and built a vetting system that reviewed 2,000 skills before developer deployment. The core insight is that shared AI skills let one developer guide another's code generation, creating a new class of supply chain risk distinct from traditional package or container threats. The call to action is to secure the entire AI-assisted development workflow, not just the generated code output.