Who Inspects the Agents? Tenable and OpenAI Turn GPT Cyber Models on Community-Built AI Components
At OpenAI's Cyber Summit, Tenable unveiled the CyberAgents Exchange AI Inspector — frontier GPT cyber models plus human researchers vetting community AI agents, skills, and MCP servers before they touch enterprise networks.
The uncomfortable question hanging over every enterprise AI rollout in 2026 is no longer “which model should we use?” It is “who checked the parts?” On September 3, at OpenAI’s Intelligence at Work: Cyber Summit, Tenable gave one concrete answer: the company is collaborating with OpenAI to build the CyberAgents Exchange AI Inspector — usually shortened to Exchange Inspector — a security review process that uses OpenAI’s restricted GPT cyber models, Tenable’s own exposure tooling, and human researchers to vet community-built AI agents, skills, MCP servers, and multi-agent playbooks before they are deployed inside enterprise environments.
The product is expected to be available in September, and it lands on a problem that has quietly become one of the sharpest edges of the agentic AI boom.
The supply chain problem nobody fully owns
Modern AI deployments are assembled, not written. A typical agent stack today pulls an orchestration framework from one repository, a handful of Model Context Protocol (MCP) servers from a community registry, packaged “skills” that give the agent capabilities like querying a ticketing system or reading a codebase, and multi-agent playbooks that wire several of these pieces together. Each component is a piece of executable logic that will, at some point, hold credentials, make network calls, or touch sensitive data.
The numbers describing this ecosystem’s hygiene are grim. Research compiled in 2026 counted more than 97 million monthly MCP downloads, with 82% of audited servers vulnerable to path traversal and only 8.5% implementing OAuth. Snyk’s ToxicSkills audit in February 2026 catalogued 1,467 malicious payloads hidden inside agent skill packages. By early 2026, roughly 7,000 internet-exposed MCP servers had been discovered, and about half ran without any authentication at all. MCP was designed for interoperability, not security — and it shows.
Enterprises responded the way enterprises do: with policy. Many simply ban community components outright, which pushes teams toward shadow IT and homegrown reimplementations that are often worse. Tenable’s bet, articulated when it launched the CyberAgents Exchange in August 2026, is that the fix is not prohibition but a trusted, inspectable registry.
What actually shipped this week
Exchange Inspector layers three review mechanisms on top of the CyberAgents Exchange, the open-source, vendor-agnostic registry Tenable launched at the beginning of August:
- Frontier assessment using OpenAI GPT cyber models. These are the restricted cybersecurity-tuned variants OpenAI makes available only to vetted defenders through its Trusted Access for Cyber program — models in the same family that OpenAI has progressively opened to security professionals since first expanding the program in April 2026. The models are pointed at community submissions to reason about what a component actually does: what it accesses, what it exfiltrates, what it could be coerced into doing.
- Skills inspection powered by Tenable One AI Exposure. Tenable’s exposure management platform already maps AI-related risk across an organization’s environment; feeding Exchange submissions through the same pipeline means inspection results arrive in the language and workflow security teams already use.
- Expert review from Tenable researchers. Machine assessment is the scale layer; humans are the judgment layer. Tenable’s researchers make final calls on what enters the registry in good standing.
The through-line from OpenAI’s side is the Daybreak Defense Network, the defensive-security coalition OpenAI has been building with cybersecurity vendors. Tenable’s participation in that program is where the collaboration originated, and the Cyber Summit — convened to showcase defensive applications of frontier AI — is where it was unveiled.
Why this pairing matters
The enterprise blocker for agentic AI in 2026 is trust in third-party components, and the quote from Eric Doerr, Tenable’s chief product officer, states the thesis plainly: “Agentic AI will only reach its potential in the enterprise if security teams can trust the components being introduced into their environments. By combining OpenAI GPT cyber models with Tenable’s security expertise and researcher review, we’re building a more rigorous way to inspect community-built AI components before they’re used in enterprise environments.”
There is a neat symmetry in using frontier models to police the frontier. OpenAI’s GPT-6 Astra — released the day before the summit — became the first model to cross the “Critical” cybersecurity capability threshold in OpenAI’s own Preparedness Framework, scoring 100% on ExploitBench and surfacing genuine zero-days in internal evaluations. Those same offensive-capable reasoning skills, wrapped in the access controls of the Trusted Access program, are exactly what make automated component inspection plausible at registry scale. A human review team cannot read a thousand MCP servers a month; a frontier model with cyber tuning can triage all of them and hand researchers the suspicious ones.
It also continues a deliberate OpenAI strategy: rather than treating powerful cyber capabilities purely as a risk to be suppressed, channel them to defenders first. Tenable becomes a case study in that approach — and a counterargument to critics who say cyber-capable models only add to the threat landscape.
The context: from Black Hat SWARM to 100+ components
The Exchange Inspector did not appear from nothing. Tenable launched the CyberAgents Exchange on August 4, 2026, calling it the industry’s first open-source, cybersecurity-native registry for AI agents, skills, MCP servers, and multi-agent playbooks. In conjunction with the launch, the company hosted SWARM, a multi-day hands-on agentic AI build event at Black Hat USA 2026 in Las Vegas. The community responded: following SWARM, the Exchange now hosts more than 100 community-submitted AI components, all open source on GitHub.
That growth is precisely why inspection became urgent. A registry with a hundred components and no review process is a target; a registry with review is infrastructure. The GitHub repository remains the content source, so the whole pipeline — submit, inspect, publish — stays auditable in public view.
Honest caveats
Some skepticism is warranted. “AI inspecting AI” is a compelling narrative, but model-based review has known failure modes: it can be evaded by obfuscated code, it inherits blind spots from its training, and a wrong verdict stamped “frontier model approved” may carry unearned confidence. The human researcher layer mitigates this but is also the bottleneck that automation is supposed to remove. Timing bears watching too — “expected to be available in September” means the Inspector has shipped as an announcement, not yet as a product enterprises can run against their own internal registries. And Tenable has a commercial interest in becoming the toll booth for agentic components; vendor-neutrality claims will be tested as competitors decide whether to submit their tools to a rival’s inspection process.
Still, the direction is right. The industry spent 2025 arguing about whether agent components needed governance; 2026’s question is who will actually build it. This week, the answer includes an unlikely pair: the company that scans enterprise attack surfaces and the company that builds the models powerful enough to attack them.
For security teams, the practical takeaway is simple. If your organization is deploying agents built from community parts, an inspection layer just became a real, scheduled product rather than a policy aspiration. And if you build such components, the bar for enterprise adoption is about to get measurably higher — inspected components will carry evidence, and uninspected ones will carry questions.
Sources
- [1] https://www.tenable.com/press-releases/tenable-uses-openai-gpt-cyber-models-to-help-defenders-inspect-community-built-ai-components
- [2] https://investors.tenable.com/news-releases/news-release-details/tenable-launches-industrys-first-open-source-ai-agent-exchange
- [3] https://github.com/tenable/cyberagents-exchange
- [4] https://www.practical-devsecops.com/mcp-security-statistics-2026-report/
- [5] https://openai.com/index/scaling-trusted-access-for-cyber-defense/