AIBound Launches IntentSentry: Detecting Malicious AI

Summary

AIBound has launched IntentSentry, a new AI security product that detects malicious agents and hidden “skills” operating inside enterprise AI assistants. During its first day of use, IntentSentry identified thousands of dangerous skills designed to steal credentials, access sensitive systems, bypass safety controls, and leak company data.

Key Takeaways
  • IntentSentry analyzes the instructions and actions behind AI agents and skills.
  • The platform detected thousands of malicious AI skills in a single day.
  • It identifies threats hidden in plain-language instructions that traditional security tools may miss.
  • IntentSentry evaluates intent in context to reduce false positives.
  • Detected risks include credential theft, sensitive-data exposure, prompt injection, excessive permissions, and safety-control bypasses.
  • The product expands AIBound’s protection from discovering AI assistants to inspecting the instructions operating inside them.
  • IntentSentry is now available to AIBound customers.
  • AIBound Launches IntentSentry: Detecting Malicious AI

    SAN FRANCISCO — July X, 2026 — AIBound, the AI security company, today launched IntentSentry, a new product that inspects both Agents, and the "skills" running inside a company's AI assistants and flags the ones that are dangerous. On its very first day of use IntentSentry uncovered thousands of malicious skills — hidden instructions built to steal passwords, access high-risk systems, or quietly leak sensitive information.

    Companies increasingly rely on AI assistants, such as Claude to get work done, and to do those jobs an AI assistant loads small add-ons called skills, instructions that teach it a single task, a bit like installing an app on your phone. But skills are easy to create and share, and a bad one can use everything the assistant can reach: its logins, its access to company systems, and its ability to send money or export files. Because the harmful instructions are written in plain language rather than obvious code, ordinary security software walks right past them. One bad skill is all it takes to hand an attacker the keys to a company's systems.

    The risk is growing fast because AI assistants are being adopted faster than companies can keep track of them. Industry analyst Gartner predicts that by 2028, one in four company security breaches will be caused by AI assistants being misused or abused (Gartner). For a business, the stakes are straightforward: a single malicious skill can lead to a data breach, financial loss, regulatory fines, and lasting damage to trust, often without anyone noticing until it's too late.

    IntentSentry closes that gap by reading every skill a company's AI assistants use and judging what it is actually trying to do, not just how it looks on the surface. Just as important, it judges intent in context, so teams see the skills that are genuinely dangerous rather than a flood of false alarms.  Because harmful skills hide their intent in ordinary language, IntentSentry examines both the plain-language instructions and the underlying actions together, so it can spot a skill that is quietly trying to steal passwords or ship HR data out of the company even when it appears perfectly normal. In early use, it caught real skills that would have caused a breach if allowed to run: one disguised as a routine helper that was secretly copying a developer's private security keys, another that tricked the assistant into ignoring its own safety rules. Both map directly to the OWASP Agentic Security Initiative's Top 10 for AI agents, spanning risks like prompt injection, sensitive data exposure, and excessive permissions that legacy scanners aren't designed to catch.

    "Malicious skills are the biggest new blind spot in enterprise AI, and the danger is that they hide in plain sight — the harmful part is written in everyday language, so traditional security tools walk right past it," said Niall Browne, Co-founder and CEO of AIBound and former Global CISO of Palo Alto Networks and Workday. "IntentSentry found thousands of these in a single day that everyone else had missed."

    "We treat every skill as untrusted and read it the way an attacker would, combining deterministic checks with layered AI review that verifies its own conclusions, so a skill that tries to talk its way past the scanner only flags itself faster," said Sunil YC, head of engineering at AIBound.

    "For the first time, we can actually answer what our AI agents are allowed to do, and who told them to do it. IntentSentry flagged risky skills in our environment that nothing else had caught," said a CISO at a health care provider.

    AIBound helps companies find every AI assistant in use, understand what each one can access, score how risky it is, and automatically stop the dangerous ones before they cause harm. With IntentSentry, that coverage now extends to the instructions inside each assistant — closing the loop from the moment an AI appears to the moment a threat is stopped.

    IntentSentry is available now to AIBound customers.

    See Your AI Attack Surface

    Discover every AI tool, agent, and model running in your enterprise — before attackers do.
    Request a Demo