Phylax (SN76) scanned 9,300 AI agent skills and packages, and roughly 20% turned out to contain hidden harmful code. SN76 has since expanded that pool past 47,000 artifacts across repositories, packages, skills, and MCP servers.
Miners compete each round to build the security agents doing the inspection, with the top three earners receiving subnet emissions per cycle.
The team has also opened an attestation catalog where verified-safe items get stamped for any agent to pull from.
The Malicious Code Problem AI Agents Already Face
Autonomous systems download software constantly during operation, with no traditional antivirus tool sitting between them and the code.

1. 20% of tested items contained hidden harmful code across the initial 9,300-artifact scan: A one-in-five hit rate exposes how vulnerable the average agent workflow currently sits.
2. Payloads frequently hide behind clean-looking README files and repository documentation: Something can present professionally while executing exploits the moment an agent activates it.
3. Attack vectors span password theft, backend access, and full system takeover: Compromised artifacts open pathways for hackers to steal keys, extract data, or hijack the systems running the agent.
Every autonomous agent in production carries this exposure unless something inspects new software before execution happens.
The Verification Pipeline Miners Run
Phylax (SN76) runs continuous rounds where security researchers submit agents to inspect four artifact categories.

1. Repositories, packages, skills, and MCP servers all get scanned: Public and private codebases both fall under coverage depending on the subscription tier accessing the pipeline.
2. Real-time verdicts return green, yellow, or red before execution: Every artifact receives a clear signal within seconds, letting the agent proceed, warn, or block cleanly.
3. Top three miners per round earn subnet emissions and auto-qualify for the next cycle: The incentive loop keeps quality high across every competition round.
4. Validators securing the subnet include Yuma, Rizzo, R21 Roundtable, and an in-house Phylax node: Multiple independent scorers protect the integrity of the emission distribution.
Every category feeds into the same attestation catalog any agent can query before pulling untrusted software.
Access Points and Business Model
Phylax delivers verification through multiple entry points designed for both technical and non-technical operators.
1. Phylax MCP server, CLI, and VS Code extension cover the primary developer entry points: Every artifact an agent tries to pull gets routed through the catalog first.

2. A GitHub-connected interface handles repo auditing for premium users on schedule: Weekly or monthly scans cover entire codebases and flag anything appearing harmful.
3. Subscription tiers span Free, Builder, Team, and Enterprise across the platform: Free lookups work at zero cost, while paid tiers unlock private repos, team access, and system-wide audits.

4. Enterprise deployments carry the highest-value B2B commercial focus: Custom features, multi-user access, and full system inspections anchor the top of the pricing ladder.
Every integration path connects back to the same shared catalog produced through continuous miner competition.
Under the Radar for Now, Not for Long
AI agents pulling code from unknown sources create a real blind spot that traditional security tools cover poorly. Phylax turned that gap into a competition on Bittensor, where researchers race to verify dependencies before attackers can bury malicious payloads inside them.
Over 47,000 scanned artifacts and a roughly 20% malicious hit rate show both the scale of the problem and the value of verifying it continuously.
Phylax is still flying under the radar, but solving a security problem this large puts it closer to commercial pipeline than most observers realize.
Enjoyed this article? Join our newsletter
Get the latest TAO & Bittensor news straight to your inbox.
We respect your privacy. Unsubscribe anytime.
Enjoyed this article?
Join our newsletter
Get the latest TAO & Bittensor news straight to your inbox — every morning before markets open.





No comments yet — be the first.