<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Supply-Chain on Technical Notes</title><link>https://luispa.com/en/tags/supply-chain/</link><description>Recent content in Supply-Chain on Technical Notes</description><generator>Hugo</generator><language>en-US</language><lastBuildDate>Sun, 24 May 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://luispa.com/en/tags/supply-chain/index.xml" rel="self" type="application/rss+xml"/><item><title>Beware of Skills</title><link>https://luispa.com/en/posts/2026-05-24-cuidado-con-las-skills/</link><pubDate>Sun, 24 May 2026 00:00:00 +0000</pubDate><guid>https://luispa.com/en/posts/2026-05-24-cuidado-con-las-skills/</guid><description>&lt;img src="https://luispa.com/img/posts/logo-cuidado-skills.svg" alt="Beware of Skills Logo" width="150px" height="150px" style="float:left; padding-right:25px" /&gt;
&lt;p&gt;Sancho is skeptical by design, and with Skills you need to be more skeptical than ever. In my note &lt;a href="https://luispa.com/en/posts/2026-01-25-sancho-aprende-skills/"&gt;&amp;ldquo;Sancho Learns Skills&amp;rdquo;&lt;/a&gt; I described how convenient it is to download a ready-made Skill and plug it into your agent. What I didn&amp;rsquo;t mention is the dark side: every Skill you download from a public marketplace is &lt;strong&gt;someone else&amp;rsquo;s code that your agent will run with your permissions&lt;/strong&gt;.&lt;/p&gt;
&lt;p&gt;That&amp;rsquo;s the new weak link in the supply chain: attackers are already poisoning these repositories with malicious Skills. In this note I lay out a few ideas to protect yourself.&lt;/p&gt;
&lt;br clear="left"/&gt;</description></item></channel></rss>