The gap isn’t that AI security tools are bad, it’s that two good ones can’t agree on what they found
Summary
The post highlights how independent AI security scanners name the same behavioral vulnerabilities differently, creating tracking and audit overhead. It introduces AVE, an open-source taxonomy of stable IDs for agentic AI vulnerability classes, noting that an independent developer's scanner findings converged on the same IDs.
Similar Articles
Realized the other day that “AI reads your instructions” and “AI reads an attacker’s instructions” look identical to it
A security researcher discusses how LLM agents cannot distinguish between user instructions and text in documents, introducing AVE, an open standard for naming AI agent vulnerabilities that is cross-referenced with OWASP and MITRE frameworks.
ClawHub Security Signals: When VirusTotal, Static Analysis, and SkillSpector Disagree
This paper investigates security scanner disagreement for AI agent skills, finding that VirusTotal, static analysis, and NVIDIA SkillSpector flag different skills with minimal overlap. It releases a sanitized dataset of over 67,000 skill versions to support further research on layered security governance.
AI and hackers - bad?
A discussion questioning whether AI's ability to find software bugs is a problem or an opportunity for companies like Google and Microsoft to proactively fix vulnerabilities.
AI research tools are still too eager to turn public signals into certainty
The author critiques AI research tools for overconfidence in weak signals, praising Komo AI's rapid discovery and source-attached summaries but highlighting the need for better uncertainty and contradiction handling. They describe a workflow that splits discovery, verification, and structured checking across multiple AI tools.
AI is breaking two vulnerability cultures
AI is disrupting traditional vulnerability disclosure cultures (coordinated disclosure vs. bugs-are-bugs) by accelerating the detection and exploitation of security flaws, making long embargoes less effective and forcing a need for faster, AI-assisted responses.