Lucas Palma argues that AI skills behave like supply-chain dependencies because their instructions can shape another developer's generated code. He identifies credential exposure, destructive shell commands and overly broad permissions as risks that a code-only review can miss.
At Nubank, a proposed skill moves through an internal marketplace gate. Developers can scan locally, then CI repeats checks after a pull request. Deterministic rules and LLM review feed pull request comments and machine-readable findings, after which policy determines whether to allow, remediate or block the skill.
Lucas Palma reports that the team scanned more than 2,000 skills and found more than 1,500 risks, with some blocked before marketplace distribution. His lessons include weighing commands by context, enforcing human approval through actual tool gates rather than prompt text alone, and extending the controls to plugins, agent rules and MCP servers.
Watch on YouTube




