Claude Code plugins can now be pinned and allow-listed. Here's what that proves, and what it doesn't.
Claude Code plugins can now be pinned to a hash and gated by an org allow list. Here's what those controls actually prove, and what they don't.
Claude Code plugins can now be pinned to a hash and gated by an org allow list. Here's what those controls actually prove, and what they don't.
An MCP registry lists skills. It does not vet them. New research shows a skill's description alone can win an agent's trust, and what you should check instead.
Shadow AI stopped being a browser tab your intern uses on the sly. It is autonomous agents and unreviewed skills now, and you cannot govern what you never wrote down.
Claude skills are easy to install and nearly impossible to vet by eye. Here is what a real certification pass looks like, layer by layer, and what each one catches.
A million scraped skills is not a catalog, it is a pile. How to find the Claude Code skills that run, do the job, and won't wreck your afternoon.
Skills, plugins, and MCP servers get used like synonyms. They are three different things at three different layers. Here is the plain-English version.
A five-minute checklist for vetting a Claude Code skill before you run it, plus what Nexus certification scans for so you don't have to.
For the past three years, every organization in America has been pitched the same thing: a chatbot. Add it to your website. Train it on your documents. Watch it answer questions. And to be fair — it worked. Sort of. Chatbots got good at answering FAQs. They reduced call volume. They
Our principles for building AI that earns trust — and how we help our clients do the same.