Tank: Building a Hardened Registry for the Agentic Era

After the ClawHavoc supply chain attacks, a new breed of package manager is enforcing "Permission Budgets" on the AI skills that run our code.

tankpkg/tank

A mechanical Trojan horse cube entering a fortress, symbolizing a malicious AI skill entering a secure terminal.
When AI agents execute untrusted code, the terminal becomes the new perimeter.

Key Takeaways

The Ghost in the Shell Access

Giving an AI agent shell access is an incredible productivity multiplier. It is also an unprecedented security vulnerability. In February 2026, the "ClawHavoc" incident proved this point at scale. Developers piping untrusted GitHub URLs into their AI assistants found that their helpful "Weather Skill" was also quietly exfiltrating SSH keys.

Tank is a security-first package manager for AI agent skills — the`npm` for the agent era, built after the ClawHavoc incident revealed that 341 malicious skills (12% of a major marketplace) were distributing credential-stealing malware.

Current agentic workflows rely on a "Wild West" model of tool distribution. Tank was built to replace this chaos with a hardened registry. It treats an AI skill not as a simple library, but as a high-risk capability that requires strict governance.

The Permission Budget

Tank introduces a core innovation called the Permission Budget. Before a skill can be installed, it must declare its intent via a manifest file. It is the spiritual successor to Deno's security model, applied directly to autonomous agents.

{
  "name": "@tank/fs-tools",
  "version": "1.0.0",
  "permissions": {
    "filesystem": ["read"],
    "network": [],
    "subprocess": false
  }
}

If a skill attempts to execute a capability outside of its declared budget, the installation is blocked. A patch version that suddenly requests outbound network access is treated as a severe security violation, effectively ending stealthy permission escalation.

A series of metal plates with geometric cutouts acting as a sieve for different shaped code blocks, catching the spiky malicious shapes.
The Permission Budget acts as a strict physical sieve, only allowing declared capabilities to pass into the agent's environment.

Inside the 6-Stage Gauntlet

The Tank registry enforces safety through a rigorous Python-based security API. Every published skill must survive a 6-stage gauntlet before it becomes available to agents.

Tank's scanning pipeline moves from basic structural checks to advanced LLM-corroborated prompt injection detection.

The pipeline progresses from simple Unicode homoglyph detection to an advanced "LLM Corroborator" in Stage 4. Because prompt injection detection is prone to false positives, Tank uses a smaller, fast LLM to distinguish between a malicious jailbreak and a benign system prompt.

Why Traditional Package Managers Fail Agents

Traditional tools like npm and PyPI were designed for human developers, not autonomous machines. They rely on post-install audits and assume the developer is verifying the code.

A malicious npm package runs inside your app's sandbox. A malicious agent skill runs with the agent's full permissions — reading any file, making API calls with your credentials, executing shell commands.

FeatureTraditional (npm/PyPI)Tank Registry
Security ModelPost-install auditPre-install Permission Budget
VersioningFeature-drivenPermission-driven SemVer
Target UserHuman DeveloperAI Agent + Human Supervisor
VerificationChecksums6-Stage Security Pipeline

Hardening the Agentic Supply Chain

The future of agentic workflows requires a "Trust but Verify" architecture. Tank provides the infrastructure needed to safely distribute capabilities across teams. By combining strict versioning, cryptographic lockfiles, and granular permission budgets, it secures the boundary between the AI model and the host machine.