<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Skill治理 on MessageDaily</title><link>https://inkeast.github.io/MessageDaily/tags/skill%E6%B2%BB%E7%90%86/</link><description>Recent content in Skill治理 on MessageDaily</description><generator>Hugo</generator><language>zh-cn</language><lastBuildDate>Mon, 14 Sep 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://inkeast.github.io/MessageDaily/tags/skill%E6%B2%BB%E7%90%86/index.xml" rel="self" type="application/rss+xml"/><item><title>Scan the Skill, Govern the Action 精读：agent 技能的「许可 ≠ 恶意」，66,192 个技能全语料测量出的运行时治理缺口</title><link>https://inkeast.github.io/MessageDaily/posts/2026-09-14-scan-skill-govern-action-oats-paper-reading/</link><pubDate>Mon, 14 Sep 2026 00:00:00 +0000</pubDate><guid>https://inkeast.github.io/MessageDaily/posts/2026-09-14-scan-skill-govern-action-oats-paper-reading/</guid><description>Pheo 团队对 ClawHub 全部 66,192 个 agent 技能版本做了测量：705 个被所有扫描器和 LLM 判官共同判为「清白」的技能，仍在指示 agent 执行 CIS/NIST 明令禁止的操作；活体实验中 agent 对 43.4% 的此类技能真的伸手，运行时门控 23/23 全部拦截。论文提出 OATS——无模型决策路径的确定性解析器 + 按资源×类别键控的信任账本 + 从操作者风险容忍度统计推导的晋升阈值，把 agent 安全从「发布时扫描」的单层世界重构为分层组合的世界。</description></item></channel></rss>