An AI Skill is a packaged capability that an agent can call on demand. Think of it like an app on a phone or an extension in a browser. The agent is the operating system, and Skills are the third-party software it installs to book travel, move funds, query a database, or sign a transaction. The convenience is obvious. So is the exposure.
A Skill can do things the user never sees. It can request more data than it needs, call an external service quietly, or trigger a financial action inside a workflow that looked routine. Most tools check a Skill the way a spell-checker reads a document, looking at content while it sits still. The risk in an agent system shows up elsewhere, during execution, when the Skill is calling functions and touching live systems.
To make this concrete: a Skill connected to a DeFi protocol might be authorized to swap tokens within a defined range. A malicious version of that Skill, indistinguishable at the code-reading level, routes the swap through a contract that extracts a fee to an attacker’s address. The user authorized a swap. The Skill executed a drain. In a Web2 context, a customer-service Skill authorized to look up one customer record can silently pull and transmit an entire database to an external endpoint. The agent completes the task normally. The data leaves without a trace. Neither attack requires the user to do anything wrong. The agent does what it was told. The Skill does something else.
This is the distinction CertiK is built around. The company says CertiK Skill Scanner evaluates risks that emerge during actual execution, including fund calls and financial transactions, across both Web3 and Web2. The point is to catch behavior that reveals itself when a Skill runs, not when it is read. The four named threat categories, hidden malicious behavior, unauthorized data access, autonomous execution risks, and fund calls with financial transactions, all share a common property: they are hardest to detect precisely because they are most severe in outcome.

How the scanner actually works
The output is deliberately simple to read. Skill Scanner returns a score from 0 to 100, attaches a verdict of pass, warn, or fail, and produces a bounded list of findings sorted by severity. A marketplace, a developer, or an enterprise compliance team can look at one number and one word and decide. CertiK states the system reaches up to 90.5 percent precision in identifying security risks, the metric that separates a useful scanner from one that floods reviewers with false alarms and gets ignored within a week.

The phrase “standardized trust layer” is carrying a precise technical argument. Existing security models verify identity, not behavior. They confirm who built a Skill and whether it was tampered with in transit. CertiK’s claim is to evaluate what the Skill does under live conditions, which is a different problem. The analogy is the difference between checking a credential and observing a clinical trial. A certificate tells you a website is who it says it is. A trial tells you whether the substance behaves safely when it runs in a real system. The trust layer Gu describes is the trial layer, not the certificate layer.

The phrase “standardized trust layer” is carrying a precise technical argument. Existing security models verify identity, not behavior. They confirm who built a Skill and whether it was tampered with in transit. CertiK’s claim is to evaluate what the Skill does under live conditions, which is a different problem. The analogy is the difference between checking a credential and observing a clinical trial. A certificate tells you a website is who it says it is. A trial tells you whether the substance behaves safely when it runs in a real system. The trust layer Gu describes is the trial layer, not the certificate layer.

The market math behind the launch
The global AI agents market was valued at $5.40 billion in 2024 and is projected to reach $50.31 billion by 2030, a compound annual growth rate of 45.8 percent. Every one of those agents is a new surface that can be attacked, and most of them are installing Skills written by someone else.

The security side is the inversion of that curve. According to Dell’Oro Group, the AI Systems Security market is forecast to grow from essentially zero to nearly $8 billion by 2030, with roughly 60 vendors already competing, anchored to an enterprise AI spend base approaching $400 billion. Dell’Oro’s analysts argue that runtime control is the decisive battleground. Runtime control means monitoring what an AI system does as it executes, observing tool calls, memory reads, agent action chains, and output behaviors as they happen, not just scanning code before deployment. That is precisely the layer CertiK is building its scan against.
The risk is not theoretical. IBM’s 2025 Cost of a Data Breach Report found that 13 percent of organizations reported breaches of AI models or applications, and 97 percent of those lacked proper AI access controls. Of the AI-related incidents, 60 percent led to compromised data and 31 percent caused operational disruption.
When the security category is a fraction of the size of the market it protects, the gap is the opportunity.
The ecosystem play
CertiK is not selling Skill Scanner as a standalone scanner. It is positioning it as infrastructure that marketplaces, enterprises, and developers wire into their pipelines, with everyday users to follow. The product has already been deployed within select Web3 AI Agent infrastructure, and CertiK is advancing an integration with FinChip.ai, a marketplace turning professional AI Skills into on-chain assets.

FinChip.ai is building a marketplace where AI Skills are tokenized on-chain assets that can be owned, traded, and earn royalties for their creators. For that market to function, Skills need to be investable. An unverified Skill is an unrated instrument: it can exist on a marketplace, but institutional users and serious developers will not integrate it at scale without knowing its risk profile. A Skill with a CertiK score is closer to a rated bond than an anonymous asset. It has disclosed risk, a standardized metric, and the ability to command a premium. The security layer is not the product of this ecosystem. It is the precondition for the product.
The launch follows a pattern. Earlier this year CertiK introduced its AI Auditor initiative, aimed at autonomous systems and AI-driven execution. Skill Scanner is the next layer on that foundation, and the roadmap points at individual users.


The reason proactive beats reactive in autonomous AI is not philosophical, it is practical. Human-supervised systems have intervention windows. An alert fires, a human reviews, a decision is made. Autonomous agents execute at machine speed, and in Web3 or financial environments, many actions cannot be undone. A Skill that routes funds on a blockchain does not wait for review. The transaction confirms in seconds. The intervention window that incident-response models depend on does not exist for this category of risk, which is the argument that makes pre-execution scanning structurally necessary rather than merely preferable.
Final Thoughts
The most interesting thing about Skill Scanner is not the antivirus metaphor. It is the placement. CertiK has spent its history auditing smart contracts and serving more than 5,000 enterprise clients, and it is applying that discipline to a category that barely had a name a year ago. The economics support the move. A scan before execution is cheaper than the cleanup after a breach, and IBM puts the average breach at $4.44 million globally and $10.22 million in the United States.

What decides whether this becomes infrastructure rather than a feature is adoption at the marketplace layer and independent validation of the 90.5 percent precision figure over time. If trust is what makes the skill economy investable, the company that sells the trust layer sits in a strong position. CertiK is making the case that the layer should exist before execution, and on the current market math, that case is hard to argue with.
Don’t forget to like and share the story!