Security company Tenable announced CyberAgents Exchange AI Inspector on September 3, 2026, a review process that vets community-submitted AI agents, skills and MCP servers before they are put to work. It layers three checks: an assessment by OpenAI cyber models, an inspection by Tenable's own product, and a human review by company researchers. Availability is expected in September.

Components of Unknown Origin Are Starting to Hold Real Privileges

Once AI agents move into production work, the hard question shifts from performance to provenance. Beyond the agent itself, there are skills that define its behavior, MCP (Model Context Protocol) servers that connect it to outside tools, and playbooks that coordinate several agents at once. The parts pile up quickly, and most of them are picked up from what other people have published.

Once running, those parts touch internal ticketing systems, cloud credentials and logging platforms. That carries far more weight than adding a single library, yet the job of checking what is inside has been left to whatever each company can do by hand. This is the gap Tenable is aiming at.

Three Layers Stacked Into One Review

Exchange Inspector works in three stages. The first is a frontier assessment using OpenAI cyber models, which read a component's behavior and description to surface risky designs and careless privilege requests. The second is a skills inspection powered by Tenable One AI Exposure, pointing the company's established exposure management machinery straight at AI components. The third is expert review by Tenable researchers, who handle the context models miss and settle the calls that come out ambiguous.

What stands out is that the automated verdict is not left to stand alone. Frontier model reasoning, a mature product-side inspection and a specialist's eye are different in character, so each one covers the weak spots of the other two. Eric Doerr, chief product officer at Tenable, has said that agentic AI will only reach its potential in the enterprise if security teams can trust the components being introduced into their environments.

The Registry Launched in August and Already Holds More Than 100 Components

The parts under review come from CyberAgents Exchange, a registry Tenable operates. It went live in August 2026 as an open-source, cybersecurity-native registry covering AI agents, skills, MCP servers and multi-agent playbooks.

Growth has been fast. After SWARM, a build event the company hosted during Black Hat USA, community-submitted components passed 100. A registry gets more useful as it fills up, and the need for vetting grows at the same rate. A company that built the registry following up with the inspection layer is a natural order of events.

A Collaboration That Came Out of OpenAI's Daybreak Network

The work grew out of Tenable's participation in Daybreak Defense Network, the framework OpenAI set up for cyber defense. The announcement venue was Intelligence at Work: Cyber Summit, an OpenAI event that gathered defensive security companies to show how frontier model reasoning is being folded into existing security products and workflows.

Several vendors have shipped implementations from that framework in the space of a few days. A division of labor, with one side supplying the models and the other side building the products, has settled in remarkably quickly. Tenable is a major exposure management vendor serving more than 40,000 customers, which puts it in a position to aim its existing inspection stack at AI components. The three-layer design carries that strength over directly.

Summary

Exchange Inspector reviews the AI agents, skills, MCP servers and multi-agent playbooks gathered in CyberAgents Exchange through three layers: OpenAI cyber models, Tenable One AI Exposure and researcher review. It is due in September. As building agents out of shared components becomes standard practice, checking what is inside those components stops being optional. Pairing a registry with a review process is a move that gets ahead of that reality.