Tenable adds OpenAI-powered security reviews for community-built AI tools
Exchange Inspector combines automated screening, model-led assessment and runtime verification. Its vetted tag applies to selected listings, not the entire CyberAgents Exchange.
Tenable’s October 8, 2026 update puts Exchange Inspector’s deeper security review into use for selected CyberAgents Exchange listings, with three skills receiving a vetted tag. The process combines Tenable’s initial screening, OpenAI GPT cyber-model assessment and a final human review that includes runtime testing. The tag is selective, not a certification of the whole directory; organizations can filter for reviewed components while still inspecting their public GitHub code before deployment.
01
The review checks 15 issue classes across model, application and infrastructure layers, including excessive permissions, credential handling and unsafe command execution.
02
Standard GPT cyber models handle baseline assessments; Daybreak Blue reviews source code and dual-use components, while Daybreak Red is reserved for higher-risk exploit validation and adversarial testing.
03
The three initial skills are SOC Hunter, Tenable’s Remediation Priority & Impact Agent, and Splunk Tenable Cloud Security Skill.
Tenable’s directory of community-built cybersecurity AI tools now has three skills carrying a deeper security-review tag. In an October 8, 2026 expansion of its CyberAgents Exchange, the company detailed how Exchange Inspector combines automated screening, OpenAI GPT cyber models and human verification to evaluate selected components before organizations deploy them.
The Exchange is a vendor-agnostic hub for agents, reusable instructions and scripts called skills, and Model Context Protocol servers that connect agents to security tools. Tenable’s technical blog says Inspector was announced in September; this update explains the review and its initial vetted listings. A baseline submission review has existed since the directory’s initial release.
From suspicious instructions to verified behavior
The first gate uses Tenable One AI Exposure’s skills-inspection engine. It examines a component’s instructions, authorized tools and permitted data access. The screening is designed to flag exposed credentials, sensitive information and prompt injection—attempts to make an AI system treat untrusted content as commands. Findings travel with the submission into deeper review.
Next, OpenAI GPT cyber models assess the component’s code and potential routes for attack. Tenable says standard models handle baseline review, while Daybreak Blue supports source-code review and components usable for both defense and attack. Daybreak Red is reserved for higher-risk submissions requiring exploit validation and adversarial testing. Inspector was developed through Tenable’s participation in OpenAI’s Daybreak Defense Network.
The model assessment considers how untrusted material could reach an agent, what a hijacked agent could do with its permissions, and whether harmless-looking steps could combine into harm. Tenable positions this as a way to identify potential threats beyond known-signature matching, rather than simply checking code against a list of previously recognized problems.
Tenable’s security researchers make the final decision. They validate earlier findings and run the component in a clean environment to check whether its behavior matches its description. Each review produces an auditable record covering provenance, the threat model, source review and runtime verification. A listing must clear all three gates to receive the vetted tag.
The review covers 15 issue classes across the model, application and infrastructure layers. Checks include excessive permissions, corrupted agent memory, credential handling, unsafe command execution and third-party dependencies. It also examines approval failures, such as an agent silently extending permission for a file edit into permission to delete files.
The first three vetted skills
The initial vetted listings include two tools built by Tenable and one by Splunk, according to Tenable. They cover threat hunting, remediation priorities and cloud-security investigations.
SOC Hunter structures proactive threat hunting for incident-response workstations. Tenable’s enterprise security team, which contributed the skill, reports a 75% reduction in hunt times.
Remediation Priority & Impact Agent builds daily vulnerability-fixing priorities using live Tenable exposure data, exploitation information and attack paths. Tenable estimates it can reduce analyst triage time by up to 20 times per cycle.
Splunk Tenable Cloud Security Skill helps teams query and triage Tenable cloud-security findings already ingested in Splunk. It uses the official Splunk MCP server and count-first query guardrails.
Sources
investors.tenable.comTenable Uses OpenAI GPT Cyber Models to Advance Agentic Security Review in the CyberAgents Exchange | Tenable, Inc.
tenable.comHow pre-vetted AI agents decrease SecOps deployment risk
Reader comments
Newest comments first. Replies stay oldest first.