AI agent security creates a weird new category:
Code-free attacks.
If a skill can influence how an agent interprets instructions, routes tools, or suppresses warnings, executable code is not required for harm.
That is very different from traditional software supply chains.
http://x.com/i/article/2037527406647316480