Back to Intelligence

Tenable Exchange Inspector: Vetting Open-Source AI Agents, Skills, and MCP Servers Before They Hit Your SOC

SA
Security Arsenal Team
October 8, 2026
12 min read

The AI agent supply chain problem stopped being theoretical the moment community-built agents, skills, and Model Context Protocol (MCP) servers started shipping directly into SOC workflows. Analysts are connecting third-party MCP servers to production LLM clients, handing them API tokens, file system access, and in some cases the ability to execute tools against live infrastructure — often with no more review than a GitHub star count.

Tenable's announcement of the Exchange Inspector — the vetting pipeline behind the "vetted" tag on its CyberAgents Exchange — is significant not because it's a marketing badge, but because it codifies a review model most organizations don't have. Every Inspector-vetted listing must clear three gates: an automated scan via Tenable One AI Exposure, an assessment by OpenAI's GPT Cyber frontier models, and human verification of runtime behavior by Tenable security researchers in a clean environment. The review tests 15 types of security issues across three layers of the stack, spanning conventional vulnerabilities like SSRF and path traversal through agent-specific failure modes like prompt injection. Three tools have passed so far.

If your SOC, detection engineering team, or IT org is deploying community AI agents today, you almost certainly don't have an equivalent gate. This post breaks down what the Inspector model tests, why each layer matters, and — critically — how to build your own version of it with detection content you can deploy now.

Technical Analysis

What the Exchange Inspector Actually Tests

The three-gate pipeline maps cleanly onto the three failure domains of AI agent supply chain risk:

Gate 1 — Automated screening (Tenable One AI Exposure). Static and configuration-level analysis targeting the two highest-frequency problems in community agent code: prompt injection surfaces and exposed secrets. This is the gate that catches the agent that hardcodes an OpenAI API key in a config file, embeds credentials in a system prompt, or concatenates untrusted tool output directly into a model context window without sanitization.

Gate 2 — Frontier model assessment (OpenAI GPT Cyber models). A large model reviews the agent's source code and threat model. This is genuinely useful for agent code specifically because the dangerous patterns are often semantic, not syntactic: a skill whose instructions tell the model to "helpfully" exfiltrate conversation context to an external endpoint won't trip a SAST rule, but a frontier model reading the prompt-and-code together can flag it. It also assesses the threat model — what tools the agent can call, what data it touches, and whether the permission scope matches the stated purpose.

Gate 3 — Human runtime verification. Tenable researchers execute the agent in a clean environment and observe actual behavior. This gate exists because gates 1 and 2 can be gamed: code that behaves benignly under review but phones home at runtime, or behavior that only manifests with specific tool outputs. Runtime verification catches DNS beacons, unexpected egress, credential file reads, and tool-call sequences that static review missed.

The 15 Issue Types Across Three Stack Layers

While Tenable's summary truncates the full list, the described range is instructive. The three layers roughly decompose as:

  • Layer 1 — Conventional application vulnerabilities in the agent's own code: SSRF (agents that fetch URLs on behalf of the model are SSRF engines by design), path traversal (file-reading skills without canonicalization checks), command injection in tool wrappers, and dependency vulnerabilities.
  • Layer 2 — Agent/protocol-specific flaws: prompt injection (direct and indirect — the latter via poisoned tool output, web content, or documents the agent ingests), excessive tool permissions, insecure MCP server transport configuration, missing output sanitization, and context-window data leakage.
  • Layer 3 — Secrets and data exposure: hardcoded API keys, tokens passed through prompts, credentials written to logs or telemetry, and secrets accessible to the model that it can be manipulated into disclosing.

Why This Matters Defensively

The exploitation requirements for a malicious or compromised MCP server are trivially low. MCP servers run locally with the user's privileges, typically hold bearer tokens for the services they integrate, and receive instructions influenced by whatever content the model has ingested. An indirect prompt injection in a webpage the agent reads can steer a malicious — or merely over-permissioned — MCP server into reading ~/.aws/credentials, writing to arbitrary paths, or POSTing context to an attacker endpoint. No memory corruption, no exploit chain — just the agent doing exactly what it was configured to allow.

Exploitation status: there is no CVE associated with this news item, and the Inspector itself is a defensive control, not a vulnerability. But the threat class it addresses — trojanized or over-privileged AI agents and MCP servers — is actively relevant in 2026, with community registries growing faster than any vendor vetting capacity. Treat every unvetted agent in your environment as unaudited third-party code with credential access, because that's what it is.

Detection & Response

The detections below target the observable behaviors that the Exchange Inspector's gates are designed to catch — so you can approximate gate 3 (runtime verification) in your own environment for agents that haven't been through any vetting.

Sigma Rules

YAML
---
title: MCP Server or AI Agent Spawning Shell or Script Interpreter
id: 3f8a2c14-7b9e-4d51-a6c3-9e1f5a2b8d04
status: experimental
description: Detects MCP servers and AI agent host processes spawning shells or script interpreters. Agent tool wrappers that shell out are a high-value target for command injection and indirect prompt injection, and unexpected shell children of an agent process warrant review.
references:
  - https://www.tenable.com/blog/tenable-openai-security-vetting-open-source-ai-agents-exchange-inspector
  - https://attack.mitre.org/techniques/T1059/
author: Security Arsenal
date: 2026/04/06
tags:
  - attack.execution
  - attack.t1059
logsource:
  category: process_creation
  product: windows
detection:
  selection_parent:
    ParentImage|endswith:
      - '\node.exe'
      - '\python.exe'
      - '\uv.exe'
      - '\uvx.exe'
      - '\npx.exe'
      - '\claude.exe'
      - '\cursor.exe'
  selection_child:
    Image|endswith:
      - '\cmd.exe'
      - '\powershell.exe'
      - '\pwsh.exe'
      - '\wscript.exe'
      - '\cscript.exe'
      - '\mshta.exe'
      - '\curl.exe'
      - '\certutil.exe'
  condition: selection_parent and selection_child
falsepositives:
  - Legitimate MCP servers that wrap CLI tools (e.g., git, cloud CLIs) — baseline known-good servers and alert on deviation
level: high
---
title: AI Agent Process Accessing Credential Stores
id: 8c1d4e72-3a6f-4b28-9d17-5e3a7c901f2b
status: experimental
description: Detects common AI agent runtimes (node, python, uv) reading browser credential stores, SSH keys, or cloud CLI credential files. A core behavior the Exchange Inspector human-verification gate is designed to catch in trojanized agents.
references:
  - https://www.tenable.com/blog/tenable-openai-security-vetting-open-source-ai-agents-exchange-inspector
  - https://attack.mitre.org/techniques/T1555/
  - https://attack.mitre.org/techniques/T1552.001/
author: Security Arsenal
date: 2026/04/06
tags:
  - attack.credential_access
  - attack.t1555
  - attack.t1552.001
logsource:
  category: process_creation
  product: windows
detection:
  selection_parent:
    ParentImage|endswith:
      - '\node.exe'
      - '\python.exe'
      - '\uv.exe'
      - '\uvx.exe'
      - '\npx.exe'
  selection_target:
    CommandLine|contains:
      - '\.aws\credentials'
      - '\.ssh\id_'
      - '\Login Data'
      - '\Cookies'
      - 'Local State'
      - '\.azure\'
      - '\.config\gcloud\'
      - 'vault'
  condition: selection_parent and selection_target
falsepositives:
  - Cloud-management MCP servers legitimately reading their own CLI credentials — scope to expected file paths per approved server
level: critical
---
title: MCP Configuration File Modified
id: 61b9e3a8-2d47-4f95-b8c2-7a1e9d305c86
status: experimental
description: Detects creation or modification of MCP server configuration files for common AI clients. Unauthorized additions to these configs are a persistence and supply-chain vector — a new MCP server entry equals new code execution with user privileges and token access.
references:
  - https://www.tenable.com/blog/tenable-openai-security-vetting-open-source-ai-agents-exchange-inspector
  - https://attack.mitre.org/techniques/T1546/
author: Security Arsenal
date: 2026/04/06
tags:
  - attack.persistence
  - attack.t1546
logsource:
  category: file_event
  product: windows
detection:
  selection:
    TargetFilename|contains:
      - 'claude_desktop_config.json'
      - '\.cursor\mcp.json'
      - '\.vscode\mcp.json'
      - 'cline_mcp_settings.json'
      - '\.mcp.json'
  condition: selection
falsepositives:
  - Developers intentionally adding MCP servers — pair with change management and an allowlist of approved servers
level: medium

KQL — Microsoft Sentinel / Defender

This hunt identifies AI agent host processes reaching out to network endpoints shortly after launch — the runtime egress pattern the Inspector's human verification gate checks for. It also surfaces agent processes making DNS or connection attempts to rare destinations, a strong indicator of a trojanized server beaconing or exfiltrating context.

KQL — Microsoft Sentinel / Defender
// Hunt: AI agent / MCP server processes with unexpected network egress
let AgentRuntimes = dynamic(["node.exe", "python.exe", "python3.exe", "uv.exe", "uvx.exe", "npx.exe", "deno.exe", "bun.exe"]);
let ApprovedMCP = dynamic(["github.com", "api.github.com", "api.openai.com", "api.anthropic.com"]); // customize per allowlist
DeviceNetworkEvents
| where TimeGenerated > ago(7d)
| where InitiatingProcessFileName in~ (AgentRuntimes)
| where isnotempty(RemoteUrl) or isnotempty(RemoteIP)
| where not(RemoteUrl has_any (ApprovedMCP))
| summarize Connections = count(),
            DistinctDestinations = dcount(RemoteIP),
            Destinations = make_set(strcat(RemoteUrl, " (", RemoteIP, ")"), 20),
            CommandLines = make_set(InitiatingProcessCommandLine, 5),
            FirstSeen = min(TimeGenerated), LastSeen = max(TimeGenerated)
    by InitiatingProcessFileName, DeviceName, InitiatingProcessAccountName
| where DistinctDestinations > 3 or Connections > 50   // tune: beaconing = low-and-slow; exfil = burst
| order by FirstSeen asc;
// Companion hunt: MCP config changes followed by first-seen process execution
DeviceFileEvents
| where TimeGenerated > ago(14d)
| where FileName has_any ("claude_desktop_config.json", "mcp.json", "cline_mcp_settings.json")
| where ActionType in ("FileCreated", "FileModified")
| project ConfigChange = TimeGenerated, DeviceName, FileName, FolderPath, InitiatingProcessFileName
| join kind=leftouter (
    DeviceProcessEvents
    | where TimeGenerated > ago(14d)
    | where ProcessCommandLine has_any ("mcp", "uvx", "npx")
    | summarize FirstExec = min(TimeGenerated), Commands = make_set(ProcessCommandLine, 10) by DeviceName, FileName
  ) on DeviceName
| project ConfigChange, DeviceName, FolderPath, FileName1, FirstExec, Commands;

Velociraptor VQL

This artifact inventories MCP/agent configurations and running agent tool chains across a fleet — the starting point for building your own vetting gate. You cannot review what you haven't inventoried.

VQL — Velociraptor
-- Inventory MCP server configurations and active agent tool processes
LET configs = SELECT FullPath, Mtime, Size,
    read_file(filename=FullPath, length=65536) AS ConfigContent
FROM glob(globs=[
  'C:/Users/*/AppData/Roaming/Claude/claude_desktop_config.json',
  'C:/Users/*/.cursor/mcp.json',
  'C:/Users/*/.vscode/mcp.json',
  'C:/Users/*/.mcp.json',
  'C:/Users/*/AppData/Roaming/Code/User/globalStorage/*/settings/cline_mcp_settings.json'
])

LET agent_procs = SELECT Pid, Ppid, Name, CommandLine, Exe, Username, CreateTime
FROM pslist()
WHERE CommandLine =~ '(?i)(mcp|modelcontextprotocol|uvx |npx .*-mcp|agent)'
  AND Name =~ '(?i)(node|python|uv|npx|deno|bun)'

LET egress = SELECT Pid, Name, ProcessExe, RemoteAddress, RemotePort, Status
FROM netstat()
WHERE Name =~ '(?i)(node|python|uv|npx|deno|bun)'
  AND Status = 'ESTABLISHED'
  AND RemoteAddress !~ '^(127\\.|10\\.|192\\.168\\.|172\\.(1[6-9]|2[0-9]|3[01])\\.)'

SELECT * FROM chain(a=configs, b=agent_procs, c=egress)

Remediation / Audit Script

Run this on Windows endpoints (or adapt for macOS/Linux paths) to inventory MCP configurations, flag unapproved servers, and scan agent config and skill directories for exposed secrets — replicating the automated portion of the Inspector's gate 1.

PowerShell
#Requires -RunAsAdministrator
# AI Agent & MCP Server Audit — approximates Exchange Inspector gate 1 (automated screening)
$report = @()

# --- 1. Inventory MCP configuration files ---
$mcpConfigPaths = @(
    "$env:APPDATA\Claude\claude_desktop_config.json",
    "$env:USERPROFILE\.cursor\mcp.json",
    "$env:USERPROFILE\.vscode\mcp.json",
    "$env:USERPROFILE\.mcp.json"
)
$approvedServers = @('github','filesystem','fetch')  # REPLACE with your vetted allowlist

foreach ($path in $mcpConfigPaths) {
    if (Test-Path $path) {
        $cfg = Get-Content $path -Raw | ConvertFrom-Json
        $servers = $cfg.mcpServers.PSObject.Properties.Name
        foreach ($s in $servers) {
            $status = if ($approvedServers -contains $s) { 'APPROVED' } else { 'UNVETTED - REVIEW REQUIRED' }
            $cmd = $cfg.mcpServers.$s.command + ' ' + ($cfg.mcpServers.$s.args -join ' ')
            $report += [pscustomobject]@{ Check='MCP-Server'; Item=$s; Detail=$cmd; Status=$status; Path=$path }
        }
    }
}

# --- 2. Scan agent/skill directories for exposed secrets (gate 1: secrets) ---
$secretPattern = '(?i)(api[_-]?key|secret|token|password|BEGIN (RSA|OPENSSH|EC) PRIVATE KEY|sk-[a-zA-Z0-9]{20,}|AKIA[0-9A-Z]{16})'
$scanDirs = @("$env:USERPROFILE\.claude", "$env:USERPROFILE\.cursor", "$env:USERPROFILE\.config\claude")
foreach ($dir in $scanDirs) {
    if (Test-Path $dir) {
        Get-ChildItem $dir -Recurse -Include *.json,*.md,*.py,*.js,*.ts,*.env,*.txt -ErrorAction SilentlyContinue |
          Where-Object { $_.Length -lt 1MB } | ForEach-Object {
            $hits = Select-String -Path $_.FullName -Pattern $secretPattern -ErrorAction SilentlyContinue
            foreach ($h in $hits) {
                $report += [pscustomobject]@{ Check='Secret'; Item=$_.Name; Detail="Line $($h.LineNumber)"; Status='POTENTIAL SECRET - ROTATE IF LIVE'; Path=$_.FullName }
            }
        }
    }
}

# --- 3. Flag agent processes with shell children (gate 3: runtime behavior) ---
Get-CimInstance Win32_Process | Where-Object {
    $_.Name -match '^(cmd|powershell|pwsh|wscript|cscript|mshta)\.exe$'
} | ForEach-Object {
    $parent = Get-CimInstance Win32_Process -Filter "ProcessId=$($_.ParentProcessId)" -ErrorAction SilentlyContinue
    if ($parent -and $parent.Name -match '^(node|python|uvx?|npx|deno|bun)\.exe$') {
        $report += [pscustomobject]@{ Check='Runtime'; Item="$($parent.Name) -> $($_.Name)"; Detail=$_.CommandLine; Status='SHELL CHILD OF AGENT - INVESTIGATE'; Path=$_.ExecutablePath }
    }
}

$report | Format-Table Check, Item, Status, Detail -AutoSize
$report | Export-Csv "$env:USERPROFILE\Desktop\ai-agent-audit-$(Get-Date -Format yyyyMMdd).csv" -NoTypeInformation
Write-Host "`nAudit complete. Review all UNVETTED and POTENTIAL SECRET findings before approving agent use."

Remediation

There is no patch here — the remediation is process. Build your own version of the Inspector's three gates before any community agent, skill, or MCP server touches production workflows:

  1. Establish an approved-agent registry now. Inventory every AI agent, MCP server, and skill currently deployed (the script and VQL above are your starting point). Anything not on the list after inventory is unapproved by default. This single step eliminates the largest exposure: agents nobody knew were running.

  2. Replicate gate 1 (automated screening) for every new listing. Before approval: run secrets scanning (e.g., gitleaks, trufflehog) against the agent's repo and installed artifacts; review all tool definitions for scope; check the transport configuration (prefer stdio with explicit allowlists over unauthenticated network transports); and map every URL the agent can fetch for SSRF exposure. Tenable One AI Exposure customers can use it for prompt-injection and secrets screening as described in the Inspector model.

  3. Replicate gate 2 (code and threat-model review). If you don't have frontier-model-assisted review, mandate a human code review checklist: prompt injection surfaces (does untrusted content flow into the model's context unsanitized?), permission scope vs. stated purpose, dependency provenance, and update mechanism (agents that self-update are supply-chain time bombs).

  4. Replicate gate 3 (runtime verification). Execute the agent in an isolated VM or container with no production credentials, instrumented with network and file monitoring. Any egress to non-allowlisted destinations, any credential-path reads, or any shell spawning that wasn't in the documented behavior fails the listing.

  5. Enforce least privilege at runtime. Run approved MCP servers under dedicated low-privilege service accounts, scope their API tokens to read-only where possible, block egress to non-allowlisted destinations via host firewall or proxy, and never run agents with ambient cloud credentials.

  6. Monitor continuously. Deploy the Sigma rules above, alert on MCP configuration changes, and diff the approved registry against observed executions weekly. A "vetted" tag — Tenable's or yours — is a point-in-time statement; version updates re-open the gate.

For teams using community agents today with no vetting at all, the priority order is: inventory, kill unapproved servers, scan for leaked secrets (rotate anything found), then build the gate.

Related Resources

Security Arsenal Penetration Testing Services AlertMonitor Platform Book a SOC Assessment vulnerability-management Intel Hub

Is your security operations ready?

Get a free SOC assessment or see how AlertMonitor cuts through alert noise with automated triage.