VYPR
researchPublished Oct 8, 2026· 1 source

Tenable's Exchange Inspector Vets Open-Source AI Agents with OpenAI Models

Tenable has launched the Exchange Inspector, a security vetting process for open-source AI agents, leveraging OpenAI's GPT models and its own AI Exposure platform.

Tenable has introduced the Exchange Inspector, a new security vetting process designed to evaluate community-built AI agents before they are listed on the CyberAgents Exchange. This initiative aims to provide security practitioners with confidence in the safety and reliability of AI tools used in Security Operations Center (SOC) workflows.

The vetting process is multi-layered, comprising three distinct stages: an automated screening, an assessment using frontier AI models, and a final human verification. This rigorous approach ensures that agents meet a high standard of security before deployment.

In the first stage, the Exchange Inspector utilizes Tenable One AI Exposure, the same technology Tenable employs to discover and assess AI agents already operating within customer environments. This automated check scans for vulnerabilities such as prompt injection, exposed secrets, hidden instructions, and excessive data access permissions. It parses the agent's instructions, its authorized tools, and the data it can access to flag potential risks.

The second stage involves the use of OpenAI's GPT Cyber models. These advanced models are employed to assess the agent's code and its associated threat model. This deep dive helps identify more complex or subtle security flaws that might be missed by automated scans alone.

Following the automated and AI model assessments, Tenable's security researchers conduct a human verification. This stage involves testing the agent's runtime behavior in a controlled, clean environment. Researchers meticulously examine the agent for 15 different types of security issues, ranging from conventional vulnerabilities like Server-Side Request Forgery (SSRF) and path traversal to agent-specific concerns such as excessive permissions and memory poisoning.

The CyberAgents Exchange itself is an open-source, vendor-agnostic directory where security professionals can discover, share, and deploy AI agents. The platform hosts agents designed for various SecOps tasks, including threat hunting, remediation triage, cloud posture investigation, and vulnerability assessment. Contributors maintain their code in public GitHub repositories, allowing users to review it before deployment.

This vetting process is crucial because AI agents, unlike typical open-source libraries, often carry credentials, interact with sensitive tools, and act upon the data they process. Their potential blast radius is significantly larger, making thorough security checks imperative, especially in light of past software supply chain attacks.

Three tools have already successfully passed the Exchange Inspector's vetting process and are listed on the CyberAgents Exchange: two developed by Tenable and one by Splunk. These vetted agents are reported to significantly accelerate threat hunting and remediation tasks, demonstrating the value of a trusted and secure AI agent ecosystem.

Synthesized by Vypr AI