LIVE · TAO
TAO$— SUBNETS VALIDATORS256
Bittensor intelligence updates
Home / AI News/ 9,300 AI Skills Tested. Phylax…
AI NEWS

9,300 AI Skills Tested. Phylax Caught 20% With Security Vulnerabilities

Phylax (SN76) scanned 47,000+ AI artifacts, exposing a 20% malicious code rate. The subnet is building a verification layer for safer agents across repos and MCP servers.

9,300 AI Skills Tested. Phylax Caught 20% With Security Vulnerabilities

Phylax (SN76) scanned 9,300 AI agent skills and packages, and roughly 20% turned out to contain hidden harmful code. SN76 has since expanded that pool past 47,000 artifacts across repositories, packages, skills, and MCP servers.

Miners compete each round to build the security agents doing the inspection, with the top three earners receiving subnet emissions per cycle.

The team has also opened an attestation catalog where verified-safe items get stamped for any agent to pull from.

The Malicious Code Problem AI Agents Already Face

Autonomous systems download software constantly during operation, with no traditional antivirus tool sitting between them and the code.

Problems Phylax Is Built To Solve

1. 20% of tested items contained hidden harmful code across the initial 9,300-artifact scan: A one-in-five hit rate exposes how vulnerable the average agent workflow currently sits.

2. Payloads frequently hide behind clean-looking README files and repository documentation: Something can present professionally while executing exploits the moment an agent activates it.

3. Attack vectors span password theft, backend access, and full system takeover: Compromised artifacts open pathways for hackers to steal keys, extract data, or hijack the systems running the agent.

Every autonomous agent in production carries this exposure unless something inspects new software before execution happens.

The Verification Pipeline Miners Run

Phylax (SN76) runs continuous rounds where security researchers submit agents to inspect four artifact categories.

How Phylax Runs Its Verification

1. Repositories, packages, skills, and MCP servers all get scanned: Public and private codebases both fall under coverage depending on the subscription tier accessing the pipeline.

2. Real-time verdicts return green, yellow, or red before execution: Every artifact receives a clear signal within seconds, letting the agent proceed, warn, or block cleanly.

3. Top three miners per round earn subnet emissions and auto-qualify for the next cycle: The incentive loop keeps quality high across every competition round.

4. Validators securing the subnet include Yuma, Rizzo, R21 Roundtable, and an in-house Phylax node: Multiple independent scorers protect the integrity of the emission distribution.

Every category feeds into the same attestation catalog any agent can query before pulling untrusted software.

Access Points and Business Model

Phylax delivers verification through multiple entry points designed for both technical and non-technical operators.

1. Phylax MCP server, CLI, and VS Code extension cover the primary developer entry points: Every artifact an agent tries to pull gets routed through the catalog first.

Catalogue of Phylax’s Product

2. A GitHub-connected interface handles repo auditing for premium users on schedule: Weekly or monthly scans cover entire codebases and flag anything appearing harmful.

3. Subscription tiers span Free, Builder, Team, and Enterprise across the platform: Free lookups work at zero cost, while paid tiers unlock private repos, team access, and system-wide audits.

Phylax’s Billing Model

4. Enterprise deployments carry the highest-value B2B commercial focus: Custom features, multi-user access, and full system inspections anchor the top of the pricing ladder.

Every integration path connects back to the same shared catalog produced through continuous miner competition.

Under the Radar for Now, Not for Long

AI agents pulling code from unknown sources create a real blind spot that traditional security tools cover poorly. Phylax turned that gap into a competition on Bittensor, where researchers race to verify dependencies before attackers can bury malicious payloads inside them.

Over 47,000 scanned artifacts and a roughly 20% malicious hit rate show both the scale of the problem and the value of verifying it continuously.

Phylax is still flying under the radar, but solving a security problem this large puts it closer to commercial pipeline than most observers realize.

Enjoyed this article? Join our newsletter

Get the latest TAO & Bittensor news straight to your inbox.

We respect your privacy. Unsubscribe anytime.

The Daily Dispatch

Enjoyed this article?
Join our newsletter

Get the latest TAO & Bittensor news straight to your inbox — every morning before markets open.

IA
Ige A
Editor-in-Chief

No comments yet — be the first.

Leave a Reply