Tank: Building a Hardened Registry for the Agentic Era
After the ClawHavoc supply chain attacks, a new breed of package manager is enforcing "Permission Budgets" on the AI skills that run our code.
- Tank secures AI agent workflows by enforcing strict permission budgets that block undeclared system capabilities.
- The registry subjects every skill to a six-stage security pipeline that includes static analysis and LLM-powered prompt injection detection.
- Unlike traditional package managers, Tank treats versioning as a permission-driven process to prevent stealthy credential exfiltration.
The Ghost in the Shell Access
Giving an AI agent shell access is an incredible productivity multiplier. It is also an unprecedented security vulnerability. In February 2026, the "ClawHavoc" incident proved this point at scale. Developers piping untrusted GitHub URLs into their AI assistants found that their helpful "Weather Skill" was also quietly exfiltrating SSH keys.
Tank is a security-first package manager for AI agent skills — the`npm` for the agent era, built after the ClawHavoc incident revealed that 341 malicious skills (12% of a major marketplace) were distributing credential-stealing malware.
Current agentic workflows rely on a "Wild West" model of tool distribution. Tank was built to replace this chaos with a hardened registry. It treats an AI skill not as a simple library, but as a high-risk capability that requires strict governance.
The Permission Budget
Tank introduces a core innovation called the Permission Budget. Before a skill can be installed, it must declare its intent via a manifest file. It is the spiritual successor to Deno's security model, applied directly to autonomous agents.
{
"name": "@tank/fs-tools",
"version": "1.0.0",
"permissions": {
"filesystem": ["read"],
"network": [],
"subprocess": false
}
}
If a skill attempts to execute a capability outside of its declared budget, the installation is blocked. A patch version that suddenly requests outbound network access is treated as a severe security violation, effectively ending stealthy permission escalation.
Inside the 6-Stage Gauntlet
The Tank registry enforces safety through a rigorous Python-based security API. Every published skill must survive a 6-stage gauntlet before it becomes available to agents.
The pipeline progresses from simple Unicode homoglyph detection to an advanced "LLM Corroborator" in Stage 4. Because prompt injection detection is prone to false positives, Tank uses a smaller, fast LLM to distinguish between a malicious jailbreak and a benign system prompt.
Why Traditional Package Managers Fail Agents
Traditional tools like npm and PyPI were designed for human developers, not autonomous machines. They rely on post-install audits and assume the developer is verifying the code.
A malicious npm package runs inside your app's sandbox. A malicious agent skill runs with the agent's full permissions — reading any file, making API calls with your credentials, executing shell commands.
| Feature | Traditional (npm/PyPI) | Tank Registry |
|---|---|---|
| Security Model | Post-install audit | Pre-install Permission Budget |
| Versioning | Feature-driven | Permission-driven SemVer |
| Target User | Human Developer | AI Agent + Human Supervisor |
| Verification | Checksums | 6-Stage Security Pipeline |
Hardening the Agentic Supply Chain
The future of agentic workflows requires a "Trust but Verify" architecture. Tank provides the infrastructure needed to safely distribute capabilities across teams. By combining strict versioning, cryptographic lockfiles, and granular permission budgets, it secures the boundary between the AI model and the host machine.