Inside the Exchange Inspector: How Tenable uses OpenAI GPT cyber models to review open
Inside the Exchange Inspector: How Tenable uses OpenAI GPT cyber models to review open-source AI agents
Community-built AI agents, skills, and MCP servers are landing in SOC workflows fast. Here’s what the Exchange Inspector tests before a listing earns its vetted tag on the CyberAgents Exchange. Three tools have already passed.
Key takeaways
- Every Inspector-vetted listing clears three gates: an automated check, a frontier model assessment, and human verification. Tenable uses Tenable One AI Exposure to screen for prompt injection and exposed secrets, and OpenAI GPT Cyber models to assess the code and threat model. Tenable security researchers then verify runtime behavior in a clean environment.
- The review tests 15 types of security issues across three layers of the stack. These issues range from conventional flaws like SSRF and path traversal vulnerabilities to agent-specific ones like excessive permissions and memory poisoning.
- Vetted tools are driving efficiencies: SOC Hunter has cut hunt times by 75% for Tenable’s security team. The CyberAgents Exchange currently has three Exchange Inspector-vetted listings: two built by Tenable and the other one by Splunk. These agents’ contributors report that they accelerate threat hunting, remediation triage, and cloud posture investigation.
Open by design, vetted before you deploy
Security teams are increasingly deploying AI agents to triage alerts, correlate threat intelligence, investigate suspicious activity, and prioritize vulnerabilities across their environments. It’s critical to know what these AI agents will do before you deploy them to a production environment. An agent carries credentials, calls tools, and acts on what it reads, so its blast radius is bigger than the one from a typical open-source library. Software supply chain attacks have taught us what happens when a registry trusts contributors by default.
The CyberAgents Exchange, powered by Tenable, is an open-source, vendor-agnostic directory for security practitioners to discover, share, and deploy agentic AI. Contributors keep their code in their own public GitHub repositories, so visitors to the CyberAgents Exchange can read it before they run it in their organizations. The directory covers a broad range of the SecOps stack:
- Agents take on the recurring, multistep work that would otherwise slow down security practitioners. AI agents autonomously plan the steps and call the security tools on their own, so analysts spend their time making decisions instead of gathering data. Current agent listings on the CyberAgents Exchange monitor scanner and platform health, assess cloud posture, map external attack paths, triage CVEs and indicators of compromise, generate remediation code, and quantify cyber risk in dollars.
- Model Context Protocol (MCP) servers connect AI agents to the tooling that security teams already use. Practitioners can analyze and act on live data in plain language instead of learning and writing API code. Current MCP server listings cover a wide gamut of vulnerability, identity, operational technology, firewall, and SecOps integrations, and expose capabilities such as mapping of MITRE ATT&CK findings and guardrailed configuration changes.
- Skills capture security experts’ methods as instructions and scripts that AI agents follow. Security practitioners get the same rigorous results on demand, without having to meticulously build their workflows from scratch. Current skill listings on the CyberAgents Exchange prioritize remediation, hunt threats, analyze malware and phishing samples, troubleshoot scans, build executive reports, and prepare compliance evidence.
- Playbooks chain agents, skills, and MCP servers into one workflow, so a whole process runs end-to-end rather than as a series of manual handoffs. Current playbook listings on the CyberAgents Exchange triage reported phishing emails, narrow thousands of findings to a few verified fixes, and coordinate entire fleets of specialized agents to facilitate multiple steps of the exposure management process.
Openness makes the CyberAgents Exchange useful, but it also makes a review process necessary. That’s why Tenable built the CyberAgents Exchange AI Inspector. We announced the Exchange Inspector in September and are now able to share some of our initial findings.
How the Exchange Inspector came to be
When Tenable created the CyberAgents Exchange, we knew each submission should receive a baseline review before being accepted into the directory, and that some submissions should receive deeper scrutiny. The baseline review has been in place since the initial release. We then created a process for performing deeper, vetted submission reviews.
The baseline review started as a manual process that was quite resource-intensive and took days to complete, depending on submission type. As the process proved effective, we converted portions of it into skills to perform data collection and analysis, and to then create artifacts for the reviewer.
How the Exchange Inspector works: Three stages, one result
The Exchange Inspector combines Tenable’s exposure detection, OpenAI’s frontier models, and human review into a single vetting process for select CyberAgents Exchange listings. We developed it through Tenable’s participation in the OpenAI Daybreak Defense Network, and it’s the first major release from that collaboration. Each stage catches a different class of problem, and a listing has to clear all three.
Stage 1: Automated screening with Tenable One AI Exposure
Every reviewed candidate listing first runs through the skills-inspection engine in Tenable One AI Exposure, using the same technology that discovers and assesses the AI agents already running across your environment.
At the time of a contribution review, the Exchange Inspector parses the agent’s instructions, the tools it’s authorized to invoke, and the data it’s permitted to reach, then flags prompt injection and jailbreak attempts, hidden instructions, hardcoded secrets, personally identifiable information (PII) exposure, and sensitive data access.
This is the fast, repeatable pass. It clears what’s obviously safe, blocks what’s obviously unsafe, and hands everything else to a deeper review with its findings attached.
Stage 2: Frontier assessment with OpenAI GPT Cyber models
The submission then moves into a frontier AI-driven assessment leveraging OpenAI GPT Cyber models available through our Daybreak access.
- Standard models handle baseline review.
- Daybreak Blue supports source code review and dual-use components.
- Daybreak Red is reserved for higher-risk submissions that need exploit validation and adversarial security testing.
Tenable uses the models to assess the full attack surface of an agent rather than relying only on known-signature matching by theorizing and testing:
- How untrusted content could reach the model
- What a hijacked or rogue agent could do with its tool permissions
- Where a chain of individually harmless actions becomes a harmful one
This is the stage that is designed to help identify potential threats that a static scanner may not surface.
Stage 3: Expert review and runtime verification
Tenable’s security research team makes the final call by:
- Validating the automated and frontier findings
- Executing the component in a clean environment to verify its runtime behavior matches its description
- Producing a durable, auditable record for every review: provenance, threat model, source review, and runtime verification. That record is what separates a vetted tag from a one-time automated pass. It can be a strong indicator of confidence for a CISO when approving a community tool for production.
What the Exchange Inspector vetted tag tells you
A listing that passes all three stages is promoted to Exchange Inspector vetted status and carries the tag on the CyberAgents Exchange. You can filter CyberAgents Exchange's search to see vetted listings only.
SOC-Hunter listing with the Exchange Inspector's vetted tag
Below you can see an excerpt of an Exchange Inspector sample report showing the provenance, threat model, source review, and runtime verification sections.
Testing for flaws with frontier reasoning across 15 issue classes
Agentic AI can have every conventional software flaw, plus an entire new class of issues of its own. Now, every model’s reasoning, memory, and tool access are part of the attack surface. Tenable identified 15 classes that every Exchange Inspector review covers at the model, application, and infrastructure layers. They’re the floor, not the ceiling. Using OpenAI GPT Cyber models, the Exchange Inspector applies frontier reasoning to assess how a threat actor could abuse a specific agent, MCP server, or skill rather than matching it against a predetermined list, surfacing flaws that don’t yet have a name.
Model layer: The agent’s reasoning and memory are the attack surface
Issues at the model layer affect the model’s reasoning, memory, and decision-making capabilities, as well as its direct interactions with users and other agents, including:
- Prompt injection and instruction hijacking: This is the manipulation of a system where the model treats untrusted content, hidden inputs, or multi-step attacks as authoritative instructions, effectively overriding system policies and blurring the boundary between data and commands.
- Excessive agency and unsafe autonomy: Granting an agent access to overly broad tools or unbounded autonomy allows it to execute potentially destructive, out-of-scope, or long-running actions without proper limits or user confirmation.
- Skill and playbook integrity: When operational playbooks or skills are manipulated, ambiguous steps, missing preconditions, or embedded commands expand the agent’s authority beyond its intended scope or act as a stealthy persistence mechanism.
- State, memory, and context integrity: The corruption or improper retention of an agent’s memory occurs when an agent saves information it shouldn’t trust, holds onto sensitive details longer than necessary, or lets one user’s data leak into someone else’s session.
- Human approval and user-intent failures: Effective user oversight breaks down when confirmation prompts hide crucial consequences, agents reuse approvals to authorize broader actions than intended, or high-impact operations are disguised within routing workflows. Some examples include approving a file edit once and silently extending that to deleting files later, or a list-alerts skill that also silently acknowledges or closes the alert.
Application layer: Most of the damage happens in the code wrapping
Issues at the application layer reside in the software wrapping the model, including how it handles data, interfaces with tools, manages permissions, and formats outputs.
- Tool and MCP server security: Weaknesses in tool implementation are characterized by inaccurate capability descriptions, missing input validation, unsafe defaults, unverified outputs, and susceptibility to various injection or protocol-spoofing attacks.
- Secrets and credential handling: The exposure or mishandling of sensitive keys, tokens, or credentials includes leaking secrets in prompts, logs, or tool outputs, granting tokens overly broad scopes, or failing to redact sensitive data from the model’s context.
- Data exfiltration and privacy: The unauthorized extraction or leakage of sensitive workspace data happens through arbitrary outbound network requests, boundary-crossing retrievals, or the improper combination of individually harmless data into sensitive conclusions.
- Output handling and downstream injection: These risks arise when unverified model outputs are directly inserted into downstream systems, leading to formula injection, terminal escapes, cross-site scripting (XSS), or the execution of unsafe generated files and links.
- Conventional application vulnerabilities: Standard software security flaws affect the surrounding application infrastructure, including injection, cross-site scripting, cross-site request forgery (CSRF), broken access control, cryptographic misuse, and business-logic flaws.
Infrastructure layer: Conventional flaws don’t disappear when a model is involved
Issues at the infrastructure layer exploit the underlying physical or virtual environments, network configurations, external dependencies, and system resources.
- Filesystem and workspace safety: Flaws allow unauthorized reading, writing, or destructive operations on a filesystem include path traversal, unsafe temporary-file handling, archive extraction vulnerabilities, and following malicious repository configurations.
- Code and command execution: Unauthorized or unsafe execution of code and commands stem from shell injections, the dynamic evaluation of model-generated code without strict sandboxing, environment manipulation, or vulnerable build scripts.
- Network and web security: Traditional and agent-specific network flaws include server-side request forgery (SSRF), open redirects, DNS rebinding, unrestricted egress, and insecure webhooks lacking proper authentication or TLS verification.
- Supply-chain and dependency risks: Vulnerabilities introduced through third-party components include unpinned packages, typosquatting, unverified artifact execution, and compromised update channels that grant excessive permissions to outside code.
- Denial of service and resource abuse: These attacks are designed to exhaust system resources or incur excessive financial costs through unbounded prompts, infinite tool loops, parser and archive bombs, queue starvation, or rate-limit bypasses.
Vetted listings are driving efficiencies
The first Exchange Inspector vetted listings are running in production today with tested, repeatable, and quantifiable results for threat hunting, cloud posture triage, and remediation prioritization.
SOC-Hunter
Built and used daily by Tenable’s enterprise security team, the SOC-Hunter skill brings structured, hypothesis-driven threat hunting to an incident responder’s terminal. It runs as a skill in Claude Code, follows the LOCK pattern (Learn, Observe, Check, Keep). It uses MCP to query:
- Security information and event management (SIEM) systems
- Endpoint detection and response (EDR) systems
- Vulnerability management systems
- Cloud security posture management (CSPM) systems
- Cloud security access brokers (CASB)
- Code search from one session
Every finding maps to MITRE ATT&CK with live Structured Threat Information eXpression (STIX) coverage analysis.
The payoff is clear and measured. A hunt that took four to six hours across eight or more browser tabs now takes 45 to 90 minutes in a single terminal, a 75% time reduction. SOC-Hunter keeps a persistent memory of past hunts, false positives, and detection gaps, so it gets sharper with every run.
Splunk Tenable Cloud Security Skill
The Splunk Tenable Cloud Security Skill lets SOC analysts and cloud security engineers investigate Tenable One Cloud Exposure findings already ingested in Splunk through an AI assistant and the official Splunk MCP Server. It ships three production-ready workflows: finding inventory, cluster and workload triage, and Tenable policy and account exposure.
What used to take more than an hour of Search Processing Language (SPL) now takes a couple of minutes using the skill, according to the Splunk contributor. Operational safety is the design center. It enforces count-first SPL guardrails, explicit time boundaries, and read-only defaults so a query can’t overwhelm the index or alter data, and it falls back to the CLI when a resource can’t be validated.
Remediation Priority & Impact Agent
The Remediation Priority & Impact Agent is an automated security tool designed to streamline vulnerability management and combat alert fatigue. By pulling data directly from a Tenable environment, the agent analyzes raw security alerts and transforms them into a highly actionable, prioritized list of necessary fixes. This tool serves as an intelligent filter that identifies exactly what to patch first.
This agent uses a multidimensional approach to risk ranking. Rather than relying solely on basic vulnerability scores, it contextualizes the Tenable data against the MITRE ATT&CK framework, specific business criticality metrics, and the overall impact of the proposed remediation. This ensures that IT and security professionals are strategically focusing their efforts on the vulnerabilities that pose the most immediate and critical threats to their business operations.
The Exchange Inspector’s vetted list will keep growing
Community-driven security only works if the community can trust what it shares. The Exchange Inspector gives practitioners insight into which AI components have been through an enterprise-grade security review and gives CISOs reliable evidence when deciding whether or not to approve them. The CyberAgents Exchange itself stays free and open-source, with no fees to list or use anything in it.
Tenable has currently reserved vetting for a handful of listings, and we’ll add more to the vetted list at our discretion as the CyberAgents Exchange grows. The same skills inspection provided as part of the Exchange Inspector review is also available for agents in your own environment through Tenable One AI Exposure. Request a demo of Tenable One AI Exposure to see the skills inspection functionality in action.
Learn more:
- Browse the Exchange Inspector vetted listings
- Read the press release "Tenable Uses OpenAI GPT Cyber Models to Advance Agentic Security Review in the CyberAgents Exchange"
- Learn more about the Exchange Inspector and the CyberAgents Exchange Security Review Process
- See Tenable AI Exposure in action, request a demo today
Learn more
- Agents
Tenable One
Request a demo
The world’s leading AI-powered exposure management platform.
Thank You
Thank you for your interest in Tenable One.
A representative will be in touch soon.
Form ID: 7469
Form Name: one-eval
Form Class: c-form form-panel__global-form c-form--mkto js-mkto-no-css js-form-hanging-label c-form--hide-comments
Form Wrapper ID: one-eval-form-wrapper
Confirmation Class: one-eval-confirmform-modal
Simulate Success
How it works
Once you click Generate, Ollama reads this article and crafts 5 comprehension questions. Your answers are graded against the article content — general knowledge won't be enough. Score 70+ to count toward your certificate.
Questions are cached — you'll always get the same 5 for this article.