
No clickbait detected — the title and thumbnail deliver what they promise.
AI Opinion
Palma convincingly argues that AI skills represent a new class of software supply chain risk requiring proactive management, drawing parallels to established library vetting processes. While the episode clearly demonstrates Nubank’s Skill Vector tool's effectiveness within their internal environment, it doesn't fully address how readily adaptable this solution would be for organizations lacking comparable resources or access to extensive training data for LLMs. Listeners should consider whether the presented model is universally applicable and investigate potential limitations when scaling similar practices across diverse organizational contexts and skill ecosystems.
Avatars are AI rewrites of the same facts — style changes, not substance.
Summary
Lucas Palma from Nubank discusses the emerging risks associated with AI skills, which he describes as critical dependencies in the software supply chain similar to traditional libraries. These skills, often created and shared by individuals, can introduce vulnerabilities such as data leaks, malicious code execution, or excessive permissions if not properly vetted. To mitigate these risks, Nubank developed "Skill Vector," an automated security review tool that combines deterministic checks with large language models for comprehensive analysis. The company’s process includes local iteration and continuous scanning of skills before they are uploaded to a trusted internal marketplace, ensuring developers only use verified AI components. Palma stresses the importance of this marketplace as a centralized hub for safe skill sharing and distribution within the organization.
Avatars are AI rewrites of the same facts — style changes, not substance.
Key Points
AI Skills as Supply Chain Dependencies
Lucas Palma explains that AI skills, like plugins and agents, now function as a critical part of the software supply chain. This means they introduce similar risks to traditional libraries and packages, requiring security review. He emphasizes that these 'skills' can be created and shared by individuals, potentially introducing vulnerabilities if not properly vetted.
Potential Dangers of AI Skills
Palma outlines several potential dangers associated with AI skills. These include unintentional data leaks through hardcoded tokens, the execution of dangerous shell commands embedded within a skill, and excessive permissions granted to a skill. He highlights that even simple typos can have significant security consequences when using shared AI skills.
Skill Vector: Automated Security Review
To address the risks associated with AI skills, Nubank developed a tool called 'Skill Vector.' This tool automatically assesses newly created or modified skills for potential vulnerabilities. It utilizes both deterministic checks (like regular expressions) and LLMs to analyze context and identify risks, ensuring a hybrid approach to security assessment.
Local Iteration & Continuous Scanning
Nubank’s process allows engineers to iterate on skills locally before uploading them to the internal marketplace. Skill Vector scans both local versions and uploaded skills, ensuring continuous security assessment throughout the development lifecycle. This iterative approach helps identify and remediate issues early in the process.
Importance of a Trusted AI Marketplace for Safe Skill Sharing
Lucas emphasizes the critical role of a 'trusted AI marketplace' to ensure safe skill sharing within Nubank. This marketplace provides a canonical way to scan and share skills, guaranteeing their safety before distribution to developers. The system encompasses both internally created skills and third-party plugins, requiring uploads for scanning and verification prior to usage.
Chapters
Claims & Fact Check
AI skills behave like supply chain dependencies.
Someone can create their own skill and share it with others, which can be dangerous.
Skill Vector uses a hybrid approach of deterministic checks and LLMs for security assessment.
Was this digest good?
More from AI Engineer

Teaching AI to Find Real Vulnerabilities — David Brumley, Bugcrowd
Aug 1, 2026

Rethinking Environments for Long-Horizon Work — Rayan Garg, Theta Software
Aug 1, 2026

What's Next After RLHF? — Diogo Almeida, TypeSafe AI
Jul 31, 2026

Data Quality Is the Compute Multiplier — Ari Morcos, DatologyAI
Jul 31, 2026
Digest any single YouTube video — free.
3 free digests — no card, no sign-up wall.
Or just swap the domain of any YouTube link → instant digest