The CyberAgents Exchange AI Inspector is live. It’s the security review behind the Exchange Inspector Vetted tag, the highest level of review a listing can currently receive on the Exchange. Engineered by Tenable to incorporate the logic of OpenAI’s frontier GPT cyber models, it was developed as part of Tenable’s participation in the OpenAI Daybreak Defense Network.
Every listing on the Exchange already clears automated screening and a baseline review by two Tenable reviewers before it goes live. Exchange Inspector vetting builds on that rather than replacing it, performing in-depth code screening over three stages.
Automated inspection with Tenable One AI Exposure. The skills inspection engine parses the agent’s instructions, the tools it can invoke, and the data it can reach, and flags prompt injection and jailbreak attempts, hidden or invisible instructions, hardcoded secrets, PII exposure, and sensitive data access.
Frontier assessment with OpenAI GPT cyber models. The models read the source and look for ways the component could be abused, beyond matching known threats: whether untrusted content can reach the model, what a hijacked agent could do with the tools it has, and whether steps that look harmless on their own add up to something harmful when chained together.
Expert review and runtime verification by Tenable security researchers. Researchers validate the automated and frontier findings, write a threat model for the component, review security-relevant surfaces in the source, and install and run the component in a clean, isolated environment using only its documented setup steps. Observed behavior is compared with what the documentation claims, and any discrepancy is a finding.
Tenable selects listings for Exchange Inspector review. The featured vetted skills at launch are SOC-Hunter, the Remediation Priority & Impact Agent, and the Splunk Tenable Cloud Security Skill, and you can filter the Exchange to show vetted listings only.
Every vetted review is anchored to a specific commit and backed by a dated security review report. What each stage covers, how findings are handled, and what a trust tier does and does not tell you are all on the Security Review Process page.
From the official release
Tenable® Holdings, Inc. (NASDAQ: TENB), the exposure management company, today announced the expansion of the CyberAgents Exchange, powered by Tenable, to further accelerate enterprise security adoption of open source AI agents, skills and MCP servers. Engineered by Tenable using OpenAI GPT cyber models, the CyberAgents Exchange AI Inspector (Exchange Inspector) evaluates selected AI components listed on the Exchange, including an enterprise-grade safety review, which is designed to help organizations more securely deploy in production environments.
“With Tenable, security teams can accelerate AI innovation while maintaining rigorous security standards,” said Vlad Korsunsky, Chief Technology Officer, Tenable. “Leveraging Tenable One AI Exposure’s advanced AI discovery engine and frontier assessment using OpenAI GPT cyber models, the Exchange Inspector provides an additional layer of review for this rapidly growing subset of agents, skills and MCP servers before deployment. The CyberAgents Exchange symbolizes trusted AI innovation, enabling CISOs and security teams to deploy AI more safely across the enterprise.”
“The cybersecurity community has come together in a truly meaningful way on the CyberAgents Exchange,” said McCall McIntyre, Head of Global Cyber Partnerships, OpenAI. “We are excited to work with Tenable on this important initiative to help deliver the trust layer required to more safely scale agentic AI across the enterprise.”
Read today’s blog, “Inside the Exchange Inspector: How Tenable and OpenAI vet open-source AI agents for production,” for more details on the CyberAgents Exchange components that have been Exchange Inspector-vetted.
Excerpted from “Tenable Uses OpenAI GPT cyber models to Advance Agentic Security Review in the CyberAgents Exchange”
Read the official release on tenable.com →