NEW YORK, May 28, 2026 (GLOBE NEWSWIRE) -- CertiK today launched CertiK Skill Scanner, a security product that evaluates third-party AI Skills before execution. The launch addresses a growing gap in AI Skill ecosystems: as marketplaces scale and Agents are granted access to more third-party tools, the security infrastructure around those Skills has not kept pace with adoption.
A New Attack Surface
Third-party AI Skills occupy a position of significant trust. They can access user data, initiate financial transactions, execute shell commands, and interact with file systems, often without any standardized review before deployment. The mechanisms that govern trust in mature software ecosystems, app review processes, behavioral sandboxing, and code signing, have not been systematically applied to AI Skills. CertiK Skill Scanner introduces that gatekeeping layer, evaluating Skills before they reach users, enterprises, or production environments.
How The Scanner Works
CertiK Skill Scanner evaluates five risk categories: malicious behavior, data exfiltration, unauthorized network activity, shell execution, and file system misuse. It accepts a GitHub repository, URL, or ZIP file as input and returns a scored assessment from 0 to 100, with pass, warn, or fail verdicts and a severity-ranked findings list. The system achieves up to 90.5% precision in identifying security risks.
A defining feature is the scanner's focus on execution-stage risks rather than static code analysis alone. Risks involving financial transactions and fund calls often only surface when a Skill is actually running, a scenario that conventional source code review tools are not designed to catch. CertiK Skill Scanner is built to evaluate those dynamic scenarios, making it particularly relevant for enterprises and platforms where AI Agents operate with financial autonomy.
Deployment Across Marketplaces, Enterprises, and Developers
The product is designed for three primary contexts. AI Skill marketplaces can embed the scanner into their publishing pipelines, reviewing Skills automatically before they go live and surfacing CertiK's verdict as a trust signal for end users. Enterprises can deploy it as a repeatable compliance process before any third-party Skill enters a production environment. Independent developers can self-audit before submission, catching and resolving issues proactively. Everyday user access is planned for a future release.
The scanner covers both Web3 and traditional Web2 ecosystems. The underlying risks, unauthorized data access, malicious execution, and network abuse, are not ecosystem-specific, and the product's scope reflects that.
Part of CertiK's Broader AI Security Push
CertiK Skill Scanner follows the AI Auditor initiative launched earlier this year and represents the company's extension of nearly a decade of blockchain and smart contract security experience into the AI domain. Smart contract environments share structural characteristics with AI Skill ecosystems: code executes autonomously, user visibility is limited, and the consequences of a security failure can be immediate and irreversible. CertiK Skill Scanner applies the same security rigor developed in those environments to a rapidly growing new category of risk.
About CertiK
Headquartered in New York and founded in 2017 by professors from Yale University and Columbia University, CertiK is the largest Web3 security services company. CertiK applies academic-grade technical rigor to the security challenges facing Web3 and AI ecosystems. The company offers full-lifecycle risk management solutions, including blockchain infrastructure assessments, smart contract audits, formal verification, penetration testing, custody architecture reviews, and compliance support. CertiK works closely with regulators and financial institutions across multiple jurisdictions, contributing to policy development and regulatory consultation efforts. To date, CertiK has partnered with more than 5,000 enterprise clients worldwide, including Binance, Ant Group, and leading banks across Europe and Singapore.
Media contact:
Elisa Yiting Xu
yiting.xu@certik.com
-
光耀盛夏,聚焦细分业态:2026古镇灯博会夏季展圆满收官中山2026年5月29日 美通社 -- 5月28日下午,随着最后一批专业买家满载而归,为期三天的2026古镇灯博会夏季展,在广东省中山市灯都古镇会议展览中心圆满闭幕。 《https2026-05-29
-
2026年全国青少年U系列腰旗橄榄球公开赛(天津站)圆满落幕“2026年全国青少年U系列腰旗橄榄球公开赛(天津站)”由中国橄榄球协会主办,天津市武清区体育局、中体场馆运营管理(天津)有限公司、天津非骁体育文化发展有限2026-05-29
-
精诚致远,第十六届世界华人保险大会系列活动峰会在12城如火如荼进行中郑州2026年5月29日 美通社 -- 2026年4月17日-6月17日,第十六届世界华人保险大会系列活动峰会在全国12个城市陆续举办,首站落地首都北京,随后奔赴西安、太原、长春、杭2026-05-29
-
湖南省商务厅召开线上会议 推动与马来西亚Halal认证合作5月27日上午,一场关于推动湖南与马来西亚Halal认证合作的线上会议在湖南省商务厅顺利举行。本次会议由中国(湖南)自由贸易试验区工作办公室专职副主任谭浩然2026-05-29
-
官宣│中国黄金推广大使梁靖崑:真金不怕火炼5月28日,中国黄金品牌官宣——乒乓球世界冠军梁靖崑担任中国黄金推广大使。 5月,2026伦敦世乒赛赛场之上,梁靖崑两度上演让二追三的逆转好戏,助力中国男团2026-05-29
-
AMD股价暴跌17%创近9年之最,苏姿丰紧急回应:AI增速远超想象
-
Ledger 中国销售渠道说明:广州馨潇贸易有限公司官方直营渠道公示
-
江苏省脑机接口产业联盟在宁成立,麦澜德分享前沿成果
-
艾芬达入选国家知识产权强国建设示范创建对象:二十载长期主义,兑现每一份用户价值
-
Esentia宣布成功完成2033年到期的6.125%优先票据和2038年到期的6.500%优先票据的定价
-
中荷人寿北京分公司成功举办中荷创享家品牌发布暨协同发展启航仪式
-
华为系具身智能公司具脑磐石完成新一轮融资:对标JEPA,押注类脑智能的认知世界模型
-
慧启赣疆 聚势共赢丨慧友酒店集团江西品鉴会书写区域文旅融合新篇
-
电影《一秒》定档:2026年,活在这一秒
-
西藏斜视患儿寒假进京手术成功,千里护航点亮视觉未来
