Back to the portfolio
The blog

Field notes.

Notes from the terminal, the incident, and the next thing to figure out.

AgentVouch

The Skills Supply Chain Attack Nobody Is Talking About

How AI agent skills create supply-chain risk, and how USDC-backed author reputation, file review, and sandboxing help inform safer installation decisions.

7 min readRead note
AgentVouch

Junk Skills: When SKILL.md Gets Ahead of Reality

Why AI skill descriptions need evidence: inspect author reputation, USDC-backed vouches, and dispute history before trusting a SKILL.md file.

3 min readRead note