Skip to content
The AI-First Web

Tenable adds a three-stage vetted tag for select open-source security AI agents

Agents carry logins and act on their own. Tenable deeply reviews a few listings; buyers should ask what that covers.

W
WebPulse Newsroom
AI-assisted · 4 min read
Share on X LinkedIn
Tenable adds a three-stage vetted tag for select open-source security AI agents
In brief
  • Tenable's Exchange Inspector puts select listings through three stages: automated scan, AI-driven attack testing, then human sign-off. Three have passed so far.
  • The review treats an agent as something that holds credentials and acts, not as a library. That is a useful frame for any team deploying agents.
  • The vetted tag is Tenable's own judgment. Ask what it tested, what it missed and who else can check it.

An AI agent is closer to a contractor with a badge than a download

Most teams vet a software library by checking who wrote it and whether it has known flaws. An AI agent needs more. It is given logins, it can trigger other software, and it takes action based on the text it reads. Tenable says a failure can therefore spread further than one in a typical open-source library.

That is the idea worth taking from Tenable's October 8 post. An agent is not a file you install. It is closer to a contractor you give a badge to. You would not hand over the badge on the strength of a public profile.

What Tenable built

Tenable runs the CyberAgents Exchange, an open-source directory of AI agents, skills and MCP servers for security teams. MCP is a standard that lets an AI assistant connect to outside tools and data. The code lives in contributors' own public GitHub repositories, open for any visitor to inspect before deploying it.

Every submission gets a baseline review before it is accepted. That review began as a manual process that took days. Tenable then turned parts of it into skills that collect and analyse data for the reviewer.

The Exchange Inspector is the deeper step, used for select listings only. Tenable announced it in September and developed it through the OpenAI Daybreak Defense Network. Tenable says openness makes the directory useful and a review process necessary.

How the three stages work

Stage one is a fast automated pass. The engine behind it is the one in Tenable's Tenable One AI Exposure product, which assesses agents already running inside a company's systems. It parses what the agent is told to do, which tools it may use and which data it can touch.

The scan looks for attempts to manipulate or jailbreak the model, concealed instructions, secrets written into the code, exposure of personal data, and access to sensitive data.

Stage two uses OpenAI GPT Cyber models. Tenable says the models assess the agent's whole attack surface by theorizing and testing, instead of matching against known signatures. The aim is to find flaws a static scanner may miss.

Stage three is human. Tenable's security research team makes the final call. A listing must clear all three stages to earn the vetted tag, and visitors can filter the directory to show vetted listings only.

3
Review stages a select listing must clear to earn the vetted tag
Source: Tenable, Exchange Inspector blog post (October 8, 2026)
15
Threat classes every review covers, across model, application and infrastructure layers
Source: Tenable, Exchange Inspector blog post (October 8, 2026)

What has passed so far

Three listings carry the tag. SOC-Hunter is a threat-hunting skill that runs in Claude Code and is used daily by Tenable's own security team. A Splunk skill lets analysts query Tenable cloud findings through the Splunk MCP Server. The third is the Remediation Priority & Impact Agent, which ranks fixes using MITRE ATT&CK and business criticality.

Tenable reports that a hunt in SOC-Hunter that took four to six hours now takes 45 to 90 minutes, a 75% reduction. For the Splunk skill, a contributor says work that took over an hour of query writing now takes a couple of minutes.

75%
Time reduction Tenable reports for a threat hunt using SOC-Hunter
Source: Tenable, Exchange Inspector blog post (October 8, 2026)

What the tag does not tell you

These are the vendor's own figures. The time savings describe what the tools do, not what the review found.

Tenable designed the review, runs it and sells the same inspection technology as part of Tenable One AI Exposure. It also says it adds vetted listings at its own discretion. The tag is therefore Tenable's judgment, not an independent audit.

The post does not say how many listings were reviewed or rejected. It also gives no measure of what the review might miss. Tenable itself calls its 15 threat classes a floor, not a ceiling.

Questions to put to your team

First, does every agent we run have an owner, a list of credentials it holds and a list of tools it can call? Second, who reads the agent's instructions and permissions before it goes live, and who rereads them after an update?

Third, when a vendor or directory says an agent is vetted, what was tested, by whom and with what result? Ask for the report, not the badge. Fourth, can we run the same checks on agents we build or adopt ourselves?

Tenable's review is one example of a sensible pattern: automated checks first, deeper testing next, a person last. The lesson is to apply that pattern to every agent you give a badge, whoever stamps the tag.

Produced by the WebPulse Newsroom with AI assistance from the original reporting credited below, and checked against that source by our editorial review. How we use AI.
Original reporting: Tenable.

Share this insight