Investment & Market Intelligence

The Investor

The Signal

Agents pulled a credential stealer 1.7 million times from a public skills marketplace.

The npm and PyPI typosquats this resembles stalled in the tens of thousands, because somewhere in the chain a human eventually read the package name and stopped. That step is gone, and nothing reviewed anything in its place. Entry multiples in agent security still sit where they did before the incident, which is either a pricing lag worth trading or a market correctly discounting a figure that rests on one unverified account. Watch which diligence checklist changes first.

In Play

  1. Agent Marketplaces Became a Malware Distribution Channel

    Two of the arcs below sit on opposite sides of one repricing clock. One has had its incident and has not been repriced; the other has absorbed its narrative without the disclosure that would justify the price. So sort diligence by whether price already contains the news. This is the side where it does not. CSO Update reports a typosquat campaign on the skills.sh agent marketplace reaching 1.7 million installs by impersonating the Paperclip and Browser Use packages and pointing agents at a GitHub-hosted credential stealer. That is a single secondary account with no named researchers, so treat the magnitude as unverified. On our own comp reading — not a published base rate — comparable typosquats on npm or PyPI stalled in the tens of thousands of installs. Either way, the install count is a market-sizing number first: agent installs at consumer scale while agent-security entry multiples still sit where they were before the incident.

    Ask Clarity
    Try
  2. AI IPO Coverage Entered Its Beneficiary Phase

    The Information has stopped asking whether Anthropic and OpenAI will list and started reporting who spends the proceeds: San Francisco real estate agents, private jet operators, and philanthropies staffing up to court AI employees as donors. The reporting discloses no valuation, timeline, or named source. On our own pattern read rather than anything in that reporting, second-order wealth coverage like this has preceded a listing by two to four quarters — which puts a clock on stale broker bid/ask and discount-to-last-round assumptions in your pre-IPO models.

    Ask Clarity
    Try
  3. Credential Theft Looks Like the Shared Payload Across Both Campaigns

    CSO Update reports a credential-stealer payload in the agent marketplace campaign and, in the same coverage, the Snowflake-customer intrusions that reached 165 companies. That it is the same payload is our inference from that single unnamed account, not a verified linkage. Connor Riley Moucka has pleaded guilty in that case and faces two to 30 years, per the same source. Non-human identity and secrets management is the highest-leverage mitigation in both incidents, which makes it the highest-leverage sales motion. The catch for your pipeline: Okta and CyberArk are already active there, so the window for a new position is narrowing rather than opening.

    Ask Clarity
    Try
  4. Prior-Generation SaaS Clears to a Cash-Flow Consolidator

    The Information reports Airtable, a category-defining no-code platform, clearing to Bending Spoons, a European consolidator, with no terms disclosed. Buyer type is the signal, not the price — the deep dive below works through what a cash-flow acquirer does to flat-growth SaaS marks.

    Ask Clarity
    Try

Deep Dives

Agent Security Is Still Priced Like Nothing Happened

The install economics of agent-mediated supply chain attacks favor the attacker structurally, three wedges are sourceable now, and the frontier labs can close two of them for free inside 18 months.

Why this campaign broke the old install ceiling

Registry typosquats have always had a natural governor, which is that somewhere in the install path a human reads the package name and something looks off. Agent marketplaces deleted that step. An agent resolves the instruction it was handed, fetches whatever the manifest points at, and reviews provenance not at all. And per CSO Update's account, the marketplace's own trending list promoted the malicious entries instead of flagging them. Distribution stopped being a constraint on the attacker and became an accelerant.

Two things follow for an allocator, and only one of them is about security. The agent install base is already at consumer-internet scale, which is a TAM statement wearing an incident statement's clothes. And the attacker's cost curve now sits structurally below the defender's, or rather it sits below and stays below, which is the precondition for a durable spend category rather than a one-quarter panic that fades with the news cycle.


The repricing reference case

Price this against post-SolarWinds software supply chain. Our own comp work, which is not a published base rate and not something in the reporting, puts entry-multiple repricing in security subsectors with a hard incident catalyst at two to four times within two to three quarters of that catalyst becoming consensus. That wave minted Chainguard, Socket, and Endor Labs, plus an acquisition path for Phylum. Agent security is still trading at pre-catalyst pricing, meaning multiples that do not yet contain the incident. The install figure will be slide three of every security deck by Q4, and slide three is where negotiating leverage goes to die.

Three wedges, one of them defensible

WedgeWhat it sellsWho could absorb itRead
Signed, provenance-verified skill and MCP registriesPublisher identity and package integrityFrontier labs, marketplace operatorsFast to fund, fastest to be commoditized
Agent runtime egress plus install allowlistingPolicy enforcement at execution timeNetwork and endpoint incumbents, slowlyThe defensible wedge
Agent identity and credential vaultingNon-human identity lifecycle, scoped secretsOkta, CyberArkReal, but the window is narrowing

The bear case belongs in the memo, not the hallway

This is a feature-versus-company problem and it should be argued out loud at IC. OpenAI and Anthropic have every incentive to ship native skill verification, and platform security vendors will bolt manifest scanning onto existing SKUs at no incremental price, which is what they do with every new attack surface. Call it a 12- to 18-month shelf life for static scanning of skill manifests. What the labs cannot hand out free is runtime policy enforcement across a heterogeneous agent fleet: multiple models, multiple registries, enterprise audit trails, switching costs that actually bite. A founder who cannot articulate why the labs won't absorb them is a pass, not a negotiation.

Static scanning of skill manifests has a 12-to-18-month shelf life. Runtime enforcement across a mixed agent fleet is the only part of this the labs cannot give away for free.

Where the evidence actually stops

One honest limit, because it changes how much weight any of this carries. The install count and the trending-list amplification detail come from a single secondary account with no named researchers and no disclosed methodology. The direction of the signal is high-confidence and actionable today. The magnitude needs a research associate and two hours of primary verification before it anchors a valuation discussion. This is probably wrong in the reassuring direction rather than the alarming one, but underwriting a category on an unverified install count is how people overpay for narrative in a hot sector. The sector is about to be hot.

What to do

  1. Commission a portfolio-wide exposure sweep within five business days: identify every portfolio company whose agents consumed public marketplace skills, require secret rotation, and confirm no egress to untrusted GitHub raw-content endpoints.

  2. Open an agent-security sourcing sprint this quarter: 8–12 first meetings across signed skill and MCP registries, runtime egress and install allowlisting, and agent credential vaulting.

  3. Add a containment gate to the AI diligence checklist before the next IC: does the product's agent install dependencies or invoke tools without human approval, and if so, are signed provenance and egress policy closing conditions?

The IPO Question Turned Into a Spending Question

The reporting discloses no valuation, timeline, or named source — the coverage stage is the entire signal, and it points at an employee supply event with two windows that disclose very differently.

A listing is not a tender, and the difference is the tell

Both labs have marked employee paper up repeatedly, which flatters morale and says nothing about liquidity. The mechanism is the interesting term: The Information reports a public listing, not a tender offer or a structured secondary, which implies private channels have not cleared employee sell demand. Unmet supply against constrained venues compresses secondary discounts to last round. Any discount-to-last-round assumption built at an earlier coverage stage describes a market that stopped existing.

Two windows, very different disclosure

Pre-listing paper carries no audited financials, no disclosure obligation, and a price set largely by broker inventory and SPV fee stacks. The post-lockup window, 90 to 180 days after a listing, inverts all of it: employees who could not clear privately sell into filings, an audited number, and observable float. Historically the second window has been the better-documented place to underwrite risk, for the unglamorous reason that the risk is visible.

This is probably wrong in one specific way: if the listing prices well and the overhang absorbs quietly, the cheap public window never opens and the compressed private paper was the better exposure all along. Model both.


The cohort the money creates

Every prior liquidity shock produced the founder cohort behind the following seed vintage: PayPal in 2002, Google in 2004, Facebook in 2012. This one tilts differently, on a read of the researcher population we cannot source to the reporting and would treat accordingly. Heavy effective-altruism affiliation among frontier researchers routes a meaningful share of the capital and attention into mission-aligned work, meaning safety, interpretability, biosecurity, mission-adjacent infrastructure. That cohort trades ownership for alignment, which is a pricing fact wearing a culture note's clothes. Fifteen relationships built this quarter are free and uncontested. The same fifteen after a lockup expiry are a bidding war.

Two exposures the model has to absorb

Retention. Mass employee cash-out reliably produces senior attrition, which is execution risk at the issuers and dependency risk at every portfolio company built on their APIs and partnership terms; a named key-person question in the memo template beats a generic one. Governance. Anthropic's mission ideology, described in The Information's coverage as a "religion" that stirred up Silicon Valley, is a genuine talent moat privately and a plausible discount publicly, because public shareholders have consistently paid less where shareholder primacy is qualified. Price that discount now rather than discovering it on pricing day.

When coverage moves from whether the listing happens to who spends the money, the uncontested part of the opportunity is the people the money will create, not the paper.

The correlation nobody is diversified against

Note what the bullish version of this story actually describes: venture marks, San Francisco housing, private aviation, and now nonprofit operating budgets, all levered to one correlated asset price. Sequoia is concentrating into the same thesis under new leadership, a claim we cannot source to today's reporting and so treat as directional, which inflates Series B and C entry prices and shortens diligence windows for everyone behind it. Every reserve dollar committed to that correlation is a dollar unavailable for the seed vintage this liquidity event produces. Run the drawdown case on NAV and reserve coverage, or the LPs will run it first.

What to do

  1. Refresh the secondaries model this week: pull bid/ask, discount-to-last-round, and SPV fee-stack data from at least three brokers, and model the post-lockup supply scenario as its own case.

  2. Stand up a named pre-liquidity relationship program this quarter: 15 target researchers across both labs, warm intros, founder-in-residence terms pre-agreed, no pitch.

  3. Commission a correlation stress test this quarter modeling NAV, follow-on reserve adequacy, and LP capital-call pacing under a 40% correction in frontier AI private marks.

Airtable's Buyer Is a Marking Tool, Not a Headline

No terms were disclosed, which is exactly why the acquirer's identity carries the information: cash-flow buyers are pricing the assets growth funds still carry at growth-era marks.

What the buyer's identity prices

The Information's account of the Airtable transaction comes with no disclosed terms, which is inconvenient for anyone building a comp table and clarifying for everyone else, because the absence pushes attention onto the one variable that actually carries information here: the buyer type. Consolidators of this kind underwrite acquired software on durable revenue and cost extraction rather than net-new growth (consolidator math, the shorthand used below), and that produces arithmetic with nothing in common with a strategic acquirer paying for a roadmap. A category-defining no-code platform clearing to a buyer like that is the most honest available read on where prior-generation SaaS transacts.

The mark that has not moved

A flat-growth SaaS position gets re-marked to that arithmetic exactly two ways, and the only interesting part is the sequencing. Either the manager does it, or an LP reading the same comp does it for them. A manager-initiated re-mark arrives with narrative control and a stated path to liquidity, which is worth something even when the number lands worse than hoped. An LP-initiated one arrives as a question answered defensively on a quarterly call, with the comp already in the LP's hands and the carrying value already looking like an argument rather than an estimate.

A limit on how far this travels: with no purchase price disclosed, this is a directional comp about buyer type, not a multiple anyone can anchor a valuation to. It tells you the clearing mechanism, not the clearing price.


Where the option value sits

The difference between a consolidator exit and a permanent hold is relationships maintained before anybody needs them. Cash-flow buyers pay for predictable revenue and reporting they do not have to rebuild, and they discount hard for whatever diligence turns up late. Three to five live acquirer dialogues per flat-growth asset costs almost nothing to maintain, which sounds like advice and is really a note on opportunity cost, since the alternative is opening those conversations at the moment an asset needs a buyer, which inverts the negotiating position, and every operator who has run that process knows the buyer can smell it. This is probably wrong in one direction or another. Maybe the comp proves idiosyncratic and prior-generation SaaS keeps clearing to strategics on friendlier arithmetic. Maybe consolidator bids become the only bids, and the flat-growth book gets marked whether or not anyone volunteers. The view here is that moving first is cheap and mostly unused. Clearing these positions is also what frees the reserve capacity that the correlated AI exposure in the IPO dive above is already competing for.

A cash-flow consolidator buying a category leader is the market telling you what growth-era SaaS is worth, without the courtesy of publishing the number.

What to do

  1. Commission a re-mark of every flat-growth SaaS position against cash-flow consolidator comparables before the next quarterly LP letter goes out.

  2. Open dialogue with three to five strategic consolidators this quarter about the portfolio's flat-growth assets, before any of them need a buyer.

The bottom line

Same clock, opposite sides: agent security is priced before its incident, frontier-lab paper is priced after its narrative and before its disclosure. That kills the habit of treating a hot sector as one condition demanding one posture. Sort every live diligence file this week by whether its price already contains the news, and put the research hours where it does not.