Skip to content
Security & Trust Talking point

When every agent shares one skill library, the vetting gate is the real safeguard

Agents that teach each other spread good lessons and bad ones alike, so the vetting step carries the weight.

W
WebPulse Newsroom
AI-assisted · 2 min read
Share on X LinkedIn
When every agent shares one skill library, the vetting gate is the real safeguard
In brief
  • Rafal Wilinski of Runlayer described agents that write skills and share them with every agent in a company, with checks before release.
  • Our angle: a shared library spreads one flawed or poisoned skill everywhere, so the vetting step matters more than the learning loop.

Rafal Wilinski, a founding engineer at Runlayer, told the AI Engineer audience that AI agents should write their own skills and share them across a whole company. A skill is a saved set of instructions for a task. He presented this as a gain. The risk side is our angle, not his: whatever enters the shared library reaches every agent at once, so the check on entry matters most.

What was said

Wilinski began with the cost of a bad start. Agents now work for longer, so they can also wander further. In his words, an agent "can spend hundreds of tool calls trying to defend a false thesis, argue for hours". He added that the next agent may repeat the mistake, or do worse.

His fix is a central server that delivers skills to company agents, using MCP, a standard way for AI apps to connect to tools. The server can enforce policies and give each person the version that fits their role.

Agents then write the skills themselves. A frontier model reviews successful and failed runs and distills a skill from them. In one test, an agent had to run a Chromium fork inside AWS Lambda, using Sonnet 4.6. It succeeded 36% of the time. After one run found a solution, the distilled skill went into later launches, and the rate rose to 100%.

Wilinski was blunt about the danger of unvetted skills. Of one popular install command, he said: "This is the only command I know that installs not just a skill, but also free prompt injections, a wild script with root privileges". He said Runlayer scans thousands of skills a day. Before a new skill reaches the library, it passes checks for prompt injections and personal data.

Why it matters

Our reading: the speed that makes the loop attractive also makes its failures dangerous. In his test, one run's solution reached every later launch. A wrong lesson, or a poisoned one, would travel the same way.

For buyers and engineering leaders, this shifts the questions. Who or what approves a skill before release? What does that check look for? Can a bad skill be traced to the run that produced it? A skill library behaves like shared code, so it deserves the same review as shared code.

The other side

The talk leaves real gaps. Wilinski gave no figures on how often the checks catch a bad skill. He said the distilling happens autonomously, without human intervention, and did not say whether a person approves a skill before release. The 36% to 100% result came from one task.

Skipping shared skills is not safe either. Wilinski argued that agents left to rediscover company routines would most likely fail, and that such failures can be costly. His server also lets a company set policies and tailor skills by role. Whether those controls are strong enough was not tested in the talk.

Written by the WebPulse Newsroom with AI assistance, and checked by our editorial review: every quotation was verified against the recording's transcript. How we use AI.

The conversation this talking point comes from

Share this insight