AI Risk Atlas Prototype/DemoUnofficial independent experiment. Not an official xAI product. Scores can be wrong.

Back to mitigations
In progress

Mandatory secret scanning before a skill can be listed

The marketplace is the control point. No scan, no publish. Rotate anything that ever leaked.

$17M experimental capital · 3 sources

Who should own it
Skill marketplaces
Platforms
How quickly it can land
Days
A crash team can ship it inside two weeks.
Expedited implementation
2 weeks
14 calendar days with a crash team
Normal implementation
2 months
60 calendar days as a planned program

Risk this mitigates

16
Agent skills leaking live credentials

Given that audits already find a few percent of public agent skills leaking live credentials during normal execution, there is a possibility of those credentials being harvested and reused by other agents or humans resulting in standing access to mail, cloud, and payment systems that no one intended to grant a model.

Residual composite 16 · still above the threshold

Effect if implemented

Applied to every failure scenario on that risk, then re-ranked. Axes are clamped at 1.

Likelihood
1
Consequence
0
Urgency
1