Control the Dependency and the Receiver
An approved skill can still load changed instructions. Production assurance needs lifecycle control over the dependency and independent authorization at the system that receives the action.
Do not approve a consequential external skill as a name or a one-time scan. The platform owner should approve exact versions and dependencies, while the receiving-system owner implements local authorization for caller, delegation, object, action, scope, freshness, and current policy.
The two-gate model
Dependency gate
Pin the accepted artifact, record bundled and remote sources, detect drift, and require review before changed instructions regain trust.
Receiver gate
Current protocols provide identity, audience, and policy primitives. The target owner must implement and prove object and action authorization locally.
Revocation proof
Close child identities, tokens, keys, queues, routes, and target sessions, then reconstruct the same authority path from the receipt.
What leaders should take from it
The skill file can point to code, packages, remote documentation, tools, credentials, identities, and services that change independently.
Current platform exclusions, a public vendor experiment, and two demoted arXiv v1 preprints support lifecycle provenance rather than a one-time badge.
The system that creates the effect should implement its own authorization policy and reject missing or excessive delegation context.
After a compromised instruction, identities, credentials, queues, routes, or sessions may remain active unless each is independently inventoried and revoked.
Evidence supports practical defenses. It does not yet establish a common enterprise loss class or a distinct security market.
Generated attack sets are not public-registry prevalence. A vendor demonstration is not a criminal incident. A scanner pass, marketplace badge, signed artifact, or parent kill switch does not prove the complete action chain safe.
First moves before hiring anyone
Record the artifact digest, signer, bundled files, packages, remote sources, tools, credential revocation handles, descendants, targets, queues, update path, and suspension owner.
The platform owner and named security or risk authorizer pin exact artifacts, withhold unreviewed mutable instructions from consequential use, scan at intake and change, preserve accepted bytes, and require reapproval after drift.
The receiving-system owner and security or IAM authorizer define accepted identities, audience, objects, actions, limits, expiry, approvals, evidence returned, denial behavior, and suspension authority. It is a technical policy unless counsel incorporates it into a commercial agreement.
Name which control closes every identity, token, key, route, queue, and session, plus the authority allowed to invoke it.
With isolated test copies, written rules from every affected owner, and approved synthetic data, prove drift detected, a negative test rejected, revocation effective, and receipt reconstructable.
Choose one external skill with a real receiving-system effect. If the dependency or receiver gate cannot pass the drill, recommend that the named security or risk owner withhold expanded authority until the missing control is fixed.
Claim ledger
No energy-sector-specific legal mapping was performed. These controls are process guidance, not legal duties, unless the authorized owners map them to the entity, system, data, deployment stage, contract, sector, and jurisdiction.
- A neutral enterprise study publishes skill prevalence, drift, receiver denials, revocation time, and escaped loss on one denominator.
- A major cross-company incident publishes the skill, identity, receiver, offboarding, and loss chain.
- A protocol, identity provider, or major platform publishes a stable delegation and receipt profile with tested cross-channel revocation.
- A regulator, auditor, insurer, or incorporated contract standard names specific agent-skill provenance or receiver-evidence duties.
- Outcome data shows whether the work becomes a distinct control category or remains part of IAM, supply chain, API security, and third-party risk.