New startup ideas · AI for people who run the AI themselves · Shadow AI made sanctioned
startup concept
Skillvet
Scan, pin and approve Agent Skills before they touch company data
A vetting service for the Agent Skills and MCP servers employees install themselves: it scans SKILL.md folders and server code for prompt injection, undisclosed network calls and data exfiltration paths, pins approved versions, and produces an approval record a power user can attach to an IT request.
- Software subscription
- Enterprise
- 'Agent Skills
1
similar startups, last 2 years (2 all-time)
no
no public money matching the concept's terms
Test it before you build it
$500 · 5 weeks · 15 prospects
Proves that enterprise security leads will pay $1,500 up front for third-party Agent Skill audits, for $500 out of pocket in 5 weeks.
Riskiest assumption · A security lead whose developers already install Agent Skills will pay a third party for vetting this quarter, rather than blocking installs outright or waiting for the registry to add built-in signing and scanning.
1Focus group: who and where
Head of application security or security engineering lead at a 500-5,000 employee software, fintech or SaaS company where developers already run Claude Code, Copilot or another assistant with Agent Skills and MCP servers, and who has fielded at least one ticket about an unapproved skill or server this quarter.
where to find 15 · The OWASP GenAI Security Project Slack (community where AppSec people discuss LLM and agent risk), local OWASP chapter meetups in SF, NYC and Austin (events, 2-3 happen every month), the Cloud Security Alliance AI working group member roster (list of exactly these titles), plus r/cybersecurity threads where admins complain about employees installing MCP servers.
2Sell first, build later
A design-partner audit pilot: we hand-audit every Agent Skill and MCP server your teams currently run - prompt injection, undisclosed network calls, data exfiltration paths - and deliver a written risk report per skill plus a pinned, approved set with an approval record, within 14 days of kickoff.
the ask · $1,500 per pilot, invoiced 100% up front, covering up to 30 skills and servers
a real yes · A real yes is the $1,500 invoice paid or the SOW signed with a kickoff date on it; 'send me the free scan first' and 'we would definitely use this once it is a product' count for nothing
3Small experiments
The first one attacks the riskiest assumption; each ends with a number that says whether to run the next.
1. Sell hand audits on 15 calls
$250 · 12 days
Book 15 calls with security leads sourced from the OWASP GenAI Slack, two OWASP chapter meetups and warm intros from former colleagues. Pitch a $1,500 paid pilot: a hand audit of every Agent Skill and MCP server their teams run, a written risk report on each, and a pinned approved set delivered in 14 days. No product exists; the audit is a founder with a checklist.
keep going if · 5 of 15 calls end with a request for the one-page SOW, and at least 3 name a kickoff date
2. Free scan demand check
$100 · 10 days
Publish a one-page site offering a free manual risk report on up to 5 skills, done by hand within 72 hours. Post it in r/ClaudeAI and r/cybersecurity and the OWASP GenAI Slack. Count submissions and how many come from corporate domains rather than hobbyists.
keep going if · 20 skill-folder submissions in 10 days, at least 5 from corporate email domains
3. Invoice the pilots
$150 · 21 days
Send the one-page SOW and an up-front invoice for $1,500 to every call that asked for it. The SOW names the 14-day delivery, up to 30 skills and servers, and the approval-record format their power users can attach to an IT request. Chase twice, then count money received.
keep going if · 2 of the SOW requests convert to a paid invoice within 21 days
4Collect a deposit up front
Tesla took $1,000 refundable reservations for the Model 3 and $100 for the Cybertruck before building either: the deposit is the measurement, not the revenue.
$1,500
per prospect, refundable
how · A paid design-partner pilot invoiced 100% up front against a one-page SOW the security lead signs, chosen because a sub-$2,000 pilot fits on a team card or a single invoice below most procurement thresholds, and because this buyer routinely pays outside firms for exactly this kind of assessment set up: Stripe Invoicing ↗
what it reserves · One of 5 audit slots in the first cohort and a locked $1,500 price for a second audit within 6 months
refund · Refunded in full if the report and pinned set are not delivered within 14 days of kickoff.
target · 2 paid pilots from 15 calls within 35 days
Go: build it if
2 paid $1,500 pilots plus 20 or more free-scan submissions with at least 5 from corporate domains: build the scanner and the team registry.
Kill: stop if
0 paid pilots after 15 calls and 5 SOWs sent, or 10 or more of the 15 leads say they will block skills entirely or wait for agentskills.io to ship signing: stop.
5 Scripts to run itoutreach message, landing copy, deposit terms · click to open
outreach message
You run security somewhere developers are already installing Agent Skills and MCP servers on their own, and the standard shipped with no signing and no scanning. I hand-audit every skill folder your teams run - prompt injection, hidden network calls, exfiltration paths - and hand you a pinned, approved set with an approval record in 14 days for $1,500. The report on your five riskiest skills is free either way. Do you have 20 minutes this week?
landing page
Know what every Agent Skill does before it touches company data $1,500 pilot: every skill and MCP server your teams run, audited and pinned in 14 days Send your five riskiest skills - the first report is free
deposit terms
The $1,500 pilot fee is invoiced up front and reserves one of five audit slots this cohort. It covers up to 30 skills and MCP servers, a written risk report on each, and a pinned approved set delivered within 14 days of kickoff. If we miss the 14-day delivery, the full fee is refunded.
Would you run this test?
One tap. The yes-share feeds the Demand pillar of this idea's score; nobody sees who answered.
Budgets are out-of-pocket estimates for a team of one to three, US market. Size the deposit to the deal, and check the terms before taking money in a regulated line.
Scorecard
Ranked against every idea in the catalog: trend, demand and 100x potential from the corpus, competition relative to the other ideas. A generated concept has no judges or swipes yet, so its pillars use the data signals only.
49
Idea Score, 0-100 (partial) · raw 30.5 x 1.61
Warm
competition: more crowded than 32% of ideas · headwind x0.84
+0.0
government priorities, secondary (0 matching grants)
Trend
41
Is the wave forming now? 2025-26 entrants vs 2023-24, rounds since 2025, the sector's live-batch direction, the 2026 trend analyst.
- Entrants 2025-26 vs 2023-24 (similar companies)74
- Rounds announced 2025+ in the sector0
- Sector direction (live batch)50
Demand
23
Does anyone want it? YC's current RFS, companies already paid for something similar, the operator judge, founders' yes-rate in decks, readers who would run the test.
- YC asks for it (current RFS: idea / sector)30
- Someone already pays (similar companies, recent / all-time)17
100x potential
50
Can it return a fund? The venture judge (double weight), market-size and moat axes, neighbours still alive, the technologist judge.
- no signal yet, taken as 50
Score = 100 x cbrt(Trend x Demand x 100x) x (1 - 0.5 x crowding) + government bonus (max 5), calibrated so the 95th-percentile idea scores 90 (order never changes). A geometric mean: a weak pillar cannot be papered over. Percentiles are among the 382 ideas in the catalog; the terms matched were scan, pin, approve, skills, touch, vetting, mcp, servers.
The concept in full
- What
- A vetting service for the Agent Skills and MCP servers employees install themselves: it scans SKILL.md folders and server code for prompt injection, undisclosed network calls and data exfiltration paths, pins approved versions, and produces an approval record a power user can attach to an IT request. In the first hour a user drags in the skills they already run, gets a risk report on each, and publishes a pinned, approved set for their team.
- Grounded in (2025-2026 signals)
- Agent Skills launched October 16, 2025 and became an open standard on December 18, 2025 (agentskills.io); by June 2026 about 40 products supported it including Claude, OpenAI Codex, GitHub Copilot, VS Code, Cursor, Gemini CLI and Goose. Since February 2026, 102 of 244 YC agent-infrastructure companies rewrote their pitch, a sign the layer is still unsettled.
- What it rides
- 'Agent Skills: launched October 16, 2025, an open standard since December 18': skills are installable folders of code and instructions with no vetting layer, exactly the gap software package managers filled a generation ago.
- Why now
- With roughly 40 products supporting Agent Skills by June 2026, skills now install across every major assistant, but the standard shipped without signing or scanning; the window is the gap between the December 18, 2025 open standard and whatever trust layer the registries eventually add.
- Wedge: first customer and entry point
- Security-conscious power users at enterprises who want their existing skill folders sanctioned; start as a free scanner with a paid team registry of pinned, approved skills.
- Closest real companies, as the generator saw them
- Confident AI (yc W25) evaluates LLM output quality and observability; Skillvet audits the supply chain of the skills and servers themselves, before anything runs.
- Main risk
- agentskills.io or the Agentic AI Foundation ships built-in signing and scanning, turning third-party vetting into a feature of the registry.
Similar startups in the directory
Companies whose pitch matches most of the concept's terms (scan, pin, approve, skills, touch, vetting, mcp, servers).
Public money in this direction
US federal grants and open opportunities matched to the concept's terms.
No matching grants or programs tracked; 19 startup-relevant grants exist in Horizontal AI assistants overall.
Other concepts in this collection
- SkillproofRegression testing for the Agent Skills you actually depend on
- ProvenaryScan third-party skills and MCP servers before you let them touch your data
- LedgerkitVersioned skill packs that make a solo CPA's assistant work like a tax practice
- VendfoldLicensing, signing and auto-update infrastructure for people who sell Agent Skills
- PackroomOne shared skill library for a team where everyone runs their own agent
- TokentabPer-skill cost, routing and drift telemetry for the person who runs AI all day
- ThreadkeepA memory vault you own that every assistant you run can read
- RelayfileHand a running task from Claude Code to Codex without losing state
- MeterhouseOne budget, meter and kill switch for every agent you run
- AttestlyAudit trail and approval inbox for the agents you run at work
- SkillvaneVersion control and regression tests for the skills your agents load
- CrewlineA shared board where each teammate's agents pick up each other's work
- WardkeySecurity scanner that finds and fixes exposed keys in vibe-coded apps
- StillupUptime and error monitoring that answers in fix prompts, not stack traces
- CopystoneAutomatic backups and one-click restore for apps built without engineers
- GroundskeepMonthly maintenance for shipped vibe-coded apps, applied as reviewable patches
- TillhousePayments, sales tax and refunds as one drop-in for non-developer founders
- SpendgateMeter, cap and route the AI spend inside apps vibe coders shipped
- DryloopRehearsal mode for the automations a small business owner builds alone
- MeterlyOne metered key with spend caps for every AI step you run
- FlowmedicWatches your automations, explains failures in plain English, proposes the fix
- ScrubdeckA data-cleaning step any workflow can call, with rules the owner keeps
- OpshandTurns your written SOPs into versioned Agent Skills with tests included
- CrewtraceShared visibility when five people at one business each run their own automations
- VeraciteCitation verification and AI work records for solo attorneys who draft with Claude
- TickstoneTurns a solo CPA's AI sessions into reviewable workpapers with tickmarks and source trails
- ChartproofA verification layer for physicians who use AI on clinical notes under their own license
- CoverlensPolicy-form verification for independent insurance agents who quote with AI
- MethodkitSolo consultants package their methodology as versioned Agent Skills they own and resell
- AttestrailTamper-evident logs of every AI action, built for licensed professionals' liability files
- ScrublineLocal redaction proxy that makes your personal AI accounts safe for work data
- StipendlyTurn personal Claude Max and ChatGPT Pro seats into managed employer stipends
- TollgateA policy gateway between your assistant and every MCP server it touches
- DaylightSelf-serve shadow AI registry and policy for companies with no security team
- LedgerlineRightsizing dashboard for everyone paying for AI out of their own pocket
- SwitchyardOne metered endpoint with routing, fallback and per-person caps for tiny teams
- HearthmeterUsage budgets and one bill for the household that shares AI plans
- SeatcaseMeasures who on your team earns a Max seat and who wastes one
- TokencairnProfiler that shows what each installed skill and MCP server really costs
- FusegateBudget caps, fallback and kill switches for automations you run yourself
- SkillbenchRegression testing for Agent Skills before every model and skill update
- CitelockVerifies every citation in AI-drafted work before a licensed professional signs it
- MiddlegateA local gateway where you set the rules for what your MCP servers can do
- DriftwatchCatches output drift in the automations small operators wired themselves
- ShipcheckPre-launch review gates non-technical builders run on their own vibe-coded apps
- TracelineA claim-level provenance trail for every number in an AI-assisted report
- DrillyardScored practice repos where you learn to drive coding agents well
- PassrateA proctored AI operation exam scored from your real agent transcripts
- PatchcraftDebugging drills that teach non-technical builders to maintain what they vibe coded
- SkillsmithA workshop for writing, testing and versioning Agent Skills that actually hold up
- TickmarkSynthetic client caseloads where CPAs drill AI-assisted work before trying it on real clients
- PostgameAn MCP server that scores your own agent sessions and drills your weakest habits
- CitegridEvery number in your published research links to a source snapshot you verified
- MnemosYour research corpus as a private MCP server every assistant can query
- MeterlineModel routing and cost accounting for one person's AI research pipeline
- SkillcaskVersion, test, and sell your expertise as licensed Agent Skills
- StackfeedA personal data pipeline that repairs itself when sources change
- ClaimboardA shared evidence ledger for small teams where everyone runs their own agent
Fictional concept generated 2026-08-26 by claude-fable-5 from the collection's brief and MarkosWeb data. Treat it as a research prompt, not a plan.