Agent Security Is Still Priced Like Nothing Happened
The install economics of agent-mediated supply chain attacks favor the attacker structurally, three wedges are sourceable now, and the frontier labs can close two of them for free inside 18 months.
Why this campaign broke the old install ceiling
Registry typosquats have always had a natural governor, which is that somewhere in the install path a human reads the package name and something looks off. Agent marketplaces deleted that step. An agent resolves the instruction it was handed, fetches whatever the manifest points at, and reviews provenance not at all. And per CSO Update's account, the marketplace's own trending list promoted the malicious entries instead of flagging them. Distribution stopped being a constraint on the attacker and became an accelerant.
Two things follow for an allocator, and only one of them is about security. The agent install base is already at consumer-internet scale, which is a TAM statement wearing an incident statement's clothes. And the attacker's cost curve now sits structurally below the defender's, or rather it sits below and stays below, which is the precondition for a durable spend category rather than a one-quarter panic that fades with the news cycle.
The repricing reference case
Price this against post-SolarWinds software supply chain. Our own comp work, which is not a published base rate and not something in the reporting, puts entry-multiple repricing in security subsectors with a hard incident catalyst at two to four times within two to three quarters of that catalyst becoming consensus. That wave minted Chainguard, Socket, and Endor Labs, plus an acquisition path for Phylum. Agent security is still trading at pre-catalyst pricing, meaning multiples that do not yet contain the incident. The install figure will be slide three of every security deck by Q4, and slide three is where negotiating leverage goes to die.
Three wedges, one of them defensible
| Wedge | What it sells | Who could absorb it | Read |
|---|---|---|---|
| Signed, provenance-verified skill and MCP registries | Publisher identity and package integrity | Frontier labs, marketplace operators | Fast to fund, fastest to be commoditized |
| Agent runtime egress plus install allowlisting | Policy enforcement at execution time | Network and endpoint incumbents, slowly | The defensible wedge |
| Agent identity and credential vaulting | Non-human identity lifecycle, scoped secrets | Okta, CyberArk | Real, but the window is narrowing |
The bear case belongs in the memo, not the hallway
This is a feature-versus-company problem and it should be argued out loud at IC. OpenAI and Anthropic have every incentive to ship native skill verification, and platform security vendors will bolt manifest scanning onto existing SKUs at no incremental price, which is what they do with every new attack surface. Call it a 12- to 18-month shelf life for static scanning of skill manifests. What the labs cannot hand out free is runtime policy enforcement across a heterogeneous agent fleet: multiple models, multiple registries, enterprise audit trails, switching costs that actually bite. A founder who cannot articulate why the labs won't absorb them is a pass, not a negotiation.
Static scanning of skill manifests has a 12-to-18-month shelf life. Runtime enforcement across a mixed agent fleet is the only part of this the labs cannot give away for free.
Where the evidence actually stops
One honest limit, because it changes how much weight any of this carries. The install count and the trending-list amplification detail come from a single secondary account with no named researchers and no disclosed methodology. The direction of the signal is high-confidence and actionable today. The magnitude needs a research associate and two hours of primary verification before it anchors a valuation discussion. This is probably wrong in the reassuring direction rather than the alarming one, but underwriting a category on an unverified install count is how people overpay for narrative in a hot sector. The sector is about to be hot.
What to do
Commission a portfolio-wide exposure sweep within five business days: identify every portfolio company whose agents consumed public marketplace skills, require secret rotation, and confirm no egress to untrusted GitHub raw-content endpoints.
Open an agent-security sourcing sprint this quarter: 8–12 first meetings across signed skill and MCP registries, runtime egress and install allowlisting, and agent credential vaulting.
Add a containment gate to the AI diligence checklist before the next IC: does the product's agent install dependencies or invoke tools without human approval, and if so, are signed provenance and egress policy closing conditions?