The Competence Gap: How Unskilled Use of AI Prompts, Agents, Skills and Code Generators Opens New Attack Surfaces in Software Systems

In July 2025 the author published a short practitioner article warning that AI-generated code frequently contains vulnerabilities. Since then the problem has changed shape: AI systems no longer only suggest code, they act. Autonomous coding agents run shell commands, connect to databases and cloud accounts through the Model Context Protocol (MCP), and load third-party "skills" from public marketplaces. This revised and expanded edition (v2.0) examines how the use of prompts, agents, skills and code generators without adequate knowledge creates new attack surfaces in systems, programs and websites. It is a structured evidence synthesis of 49 sources (peer-reviewed papers, preprints, large-scale vendor measurements, CVE records, incident disclosures, and official standards from OWASP, NIST, ISO/IEC and the European Union). It also includes a qualitative coding of 14 landmark incidents from 2025–2026 against seven risk factors. Key findings: about 45% of AI-generated code samples fail security tests, a rate that has not improved as models improved. Public agent-skill marketplaces show a security flaw in 36.8% of skills and a critical flaw in 13.4%, and one audit found 341 malicious skills in a single registry. Of 9,695 public MCP servers examined, 2,259 had confirmed vulnerabilities. Leaks of AI-service credentials on GitHub rose 81% in 2025. In the incident sample, prompt injection, excessive agency and exposed credentials each appeared in 8 of 14 cases, and a knowledge gap on the part of the operator contributed to 7. The article proposes the Competence-Aware Defense-in-Depth (CADD) model: five control layers and a four-level maturity scale that tie the autonomy granted to an AI system to the demonstrated competence of the people operating it. It includes 15 figures, 9 tables, an incident catalogue, a 20-question vetting checklist for skills and MCP servers, a glossary, and secure prompt templates. Declaration: AI tools assisted with literature search, drafting, visualization and typesetting. All sources were checked by the author, who is responsible for all interpretations.

Authors

Publication Details

Journal
Zenodo (CERN European Organization for Nuclear Research)
Published
2026-09-30
DOI
https://doi.org/10.5281/zenodo.23065786
Primary Topic
Information and Cyber Security
Type
article
Field-Weighted Citation Impact
0.00
Controls
|||
ALL TIME
JAN
FEB
MAR
APR
MAY
JUN
JUL
AUG
SEP
article

The Competence Gap: How Unskilled Use of AI Prompts, Agents, Skills and Code Generators Opens New Attack Surfaces in Software Systems

WESLEY HARUO KUROSAWA DA SILVA
Zenodo (CERN European Organization for Nuclear Research)
Information and Cyber Security
article

The Competence Gap: How Unskilled Use of AI Prompts, Agents, Skills and Code Generators Opens New Attack Surfaces in Software Systems

WESLEY HARUO KUROSAWA DA SILVA
article en

Abstract

In July 2025 the author published a short practitioner article warning that AI-generated code frequently contains vulnerabilities. Since then the problem has changed shape: AI systems no longer only suggest code, they act. Autonomous coding agents run shell commands, connect to databases and cloud accounts through the Model Context Protocol (MCP), and load third-party "skills" from public marketplaces. This revised and expanded edition (v2.0) examines how the use of prompts, agents, skills and code generators without adequate knowledge creates new attack surfaces in systems, programs and websites. It is a structured evidence synthesis of 49 sources (peer-reviewed papers, preprints, large-scale vendor measurements, CVE records, incident disclosures, and official standards from OWASP, NIST, ISO/IEC and the European Union). It also includes a qualitative coding of 14 landmark incidents from 2025–2026 against seven risk factors. Key findings: about 45% of AI-generated code samples fail security tests, a rate that has not improved as models improved. Public agent-skill marketplaces show a security flaw in 36.8% of skills and a critical flaw in 13.4%, and one audit found 341 malicious skills in a single registry. Of 9,695 public MCP servers examined, 2,259 had confirmed vulnerabilities. Leaks of AI-service credentials on GitHub rose 81% in 2025. In the incident sample, prompt injection, excessive agency and exposed credentials each appeared in 8 of 14 cases, and a knowledge gap on the part of the operator contributed to 7. The article proposes the Competence-Aware Defense-in-Depth (CADD) model: five control layers and a four-level maturity scale that tie the autonomy granted to an AI system to the demonstrated competence of the people operating it. It includes 15 figures, 9 tables, an incident catalogue, a 20-question vetting checklist for skills and MCP servers, a glossary, and secure prompt templates. Declaration: AI tools assisted with literature search, drafting, visualization and typesetting. All sources were checked by the author, who is responsible for all interpretations.

Zenodo (CERN European Organization for Nuclear Research)
Quality Education
Openalex Percentile: Top 4%
Information and Cyber Security
AI Navigator

Ask Laika to Summarize, Analyze, and Connect papers live on the map.

Summarize Papers & Methodologies

Extract key findings, datasets, and comparative methods across publications.

Benchmark Rankings & Visual Analytics

Rank top research institutions, authors, funders, topics, and journals by Field-Weighted Citation Impact (FWCI) and paper volume with instant charts.

Connect Distant Disciplines

Bridge topological clusters on the map to find hidden collaborative intersections.

The Competence Gap: How Unskilled Use of AI Prompts, Agents, Skills and Code Generators Opens New Attack Surfaces in Software Systems — WESLEY HARUO KUROSAWA DA SILVA · Zenodo (CERN European Organization for Nuclear Research) (2026) | TGRS Research Map | TGRS