We Vetted 2000 AI Skills Before They Reached Developers — Lucas Palma, Nubank

AI Engineer16mJul 29, 2026
Watch Original (opens in new tab)
0:00 / 16:24
Chapters6

No clickbait detected — the title and thumbnail deliver what they promise.

AI Opinion

Palma convincingly argues that AI skills represent a new class of software supply chain risk requiring proactive management, drawing parallels to established library vetting processes. While the episode clearly demonstrates Nubank’s Skill Vector tool's effectiveness within their internal environment, it doesn't fully address how readily adaptable this solution would be for organizations lacking comparable resources or access to extensive training data for LLMs. Listeners should consider whether the presented model is universally applicable and investigate potential limitations when scaling similar practices across diverse organizational contexts and skill ecosystems.

Avatars are AI rewrites of the same facts — style changes, not substance.

Summary

Lucas Palma from Nubank discusses the emerging risks associated with AI skills, which he describes as critical dependencies in the software supply chain similar to traditional libraries. These skills, often created and shared by individuals, can introduce vulnerabilities such as data leaks, malicious code execution, or excessive permissions if not properly vetted. To mitigate these risks, Nubank developed "Skill Vector," an automated security review tool that combines deterministic checks with large language models for comprehensive analysis. The company’s process includes local iteration and continuous scanning of skills before they are uploaded to a trusted internal marketplace, ensuring developers only use verified AI components. Palma stresses the importance of this marketplace as a centralized hub for safe skill sharing and distribution within the organization.

Avatars are AI rewrites of the same facts — style changes, not substance.

Key Points

01:37

AI Skills as Supply Chain Dependencies

Lucas Palma explains that AI skills, like plugins and agents, now function as a critical part of the software supply chain. This means they introduce similar risks to traditional libraries and packages, requiring security review. He emphasizes that these 'skills' can be created and shared by individuals, potentially introducing vulnerabilities if not properly vetted.

04:41

Potential Dangers of AI Skills

Palma outlines several potential dangers associated with AI skills. These include unintentional data leaks through hardcoded tokens, the execution of dangerous shell commands embedded within a skill, and excessive permissions granted to a skill. He highlights that even simple typos can have significant security consequences when using shared AI skills.

05:50

Skill Vector: Automated Security Review

To address the risks associated with AI skills, Nubank developed a tool called 'Skill Vector.' This tool automatically assesses newly created or modified skills for potential vulnerabilities. It utilizes both deterministic checks (like regular expressions) and LLMs to analyze context and identify risks, ensuring a hybrid approach to security assessment.

07:12

Local Iteration & Continuous Scanning

Nubank’s process allows engineers to iterate on skills locally before uploading them to the internal marketplace. Skill Vector scans both local versions and uploaded skills, ensuring continuous security assessment throughout the development lifecycle. This iterative approach helps identify and remediate issues early in the process.

15:06

Importance of a Trusted AI Marketplace for Safe Skill Sharing

Lucas emphasizes the critical role of a 'trusted AI marketplace' to ensure safe skill sharing within Nubank. This marketplace provides a canonical way to scan and share skills, guaranteeing their safety before distribution to developers. The system encompasses both internally created skills and third-party plugins, requiring uploads for scanning and verification prior to usage.

Chapters

6 chapters · 5 key moments
KEYkey momentNot checkable herePartially supported

Claims & Fact Check

AI skills behave like supply chain dependencies.

Not checkable here

Someone can create their own skill and share it with others, which can be dangerous.

Not checkable here

Skill Vector uses a hybrid approach of deterministic checks and LLMs for security assessment.

±Partially supported

Was this digest good?

More from AI Engineer

Digest any single YouTube video — free.

3 free digests — no card, no sign-up wall.

Or just swap the domain of any YouTube link → instant digest