Week of October 4 – October 10, 2026
The Skills Became a Supply Chain, and My Pull Finally Saw the Industry
By Kin Lane · Sent October 12, 2026
I have to start with a correction to my own instrument, because it changes every number in this issue.
This newsletter is built from a weekly pull of the blogs of the API providers I track. On Tuesday I went looking for providers that did not have a blog on record, and found something worse: for most of the providers that did, my pull was reading the wrong page. The configuration pairs each entry’s type with its URL, and when an entry listed the type first, the script was taking the URL from the entry above it. Of 15,748 providers that declare a blog, 12,624 were being pulled from something else — their privacy policy, their pricing page, their contact form.
That is fixed, and I added 4,954 blogs I had not been watching at all. So this week I read 12,767 posts from 2,795 provider blogs, up from 7,816 posts from 1,705 blogs the week before. Do not read that as the industry doubling its output in seven days. It is me finally seeing more of what was already there, and it means this week’s counts are not comparable with any earlier issue. I will rebuild the trend lines from here.
The good news is that the wider lens made the week’s story easier to see, not harder.

Agent Skills Became a Supply Chain
Three weeks ago I wrote that Skills over MCP is final, and now it needs servers. This week one of the biggest arrived: the Cloudflare API MCP server now serves Cloudflare skills through the Skills over MCP extension. Clients that support it discover them with skills/list and read the files at skill:// URIs. A skill is no longer a folder you copy into a repo. It is something a server hands an agent at connection time.
The same week, the security industry started treating skills the way it treats packages.
- VirusTotal published part three of its study of malicious agent skills, expanding from 3,016 skills to 35,878, and naming, measuring and detecting the ones that carry a payload. Tessl’s talk from AI Native DevCon London makes the framing explicit: agent skills are supply chain components. And Port reviewed JFrog’s Agent Skills Registry — once the artifact-repository vendors build a registry for something, it has become a dependency.
- The supply chain also got hit in the ordinary way. Socket caught a compromised release of the TensorLake npm SDK — version 0.5.144, the SDK for an AI agent infrastructure company — carrying credential-stealing malware in a ChainDrop / Shai-Hulud attack. Cloudsmith wrote it up too.
- Meanwhile the legitimate skills kept shipping. AWS published an agent skill for SageMaker-optimized inference through its Agent Toolkit. Wagtail released agent skills for its developers. Sentry’s plugin adds tools and skills to Unreal Engine’s new Unreal MCP.
Put those together and the shape is clear. Skills are now distributed by servers, consumed by agents, and attacked like packages — all in the same week. The thing nobody has yet is the provenance layer between them: who wrote this skill, what it is allowed to do, and whether the copy your agent just loaded is the one that was published.


MCP Authentication Grew Patterns
Two weeks ago the MCP auth story was a list of bugs. This week it was a list of patterns, which is what maturity looks like from the outside.
- Okta showed how to build a secure TypeScript MCP client with Cross App Access — one enterprise app calling another on a user’s behalf, with the identity provider in the middle rather than a token pasted into a config file.
- Autodesk published authentication patterns for MCP servers on its platform, following its earlier guide to building them. A platform writing down its auth patterns is a platform expecting other people to build servers on it.
- MuleSoft wrote up a proxy pattern for governing remote MCP servers built around RFC 9728 protected-resource metadata — including the detail that the
resourcefield must match the URL the client called byte for byte, which is exactly what breaks when you put a gateway in front. - WorkOS explained why Figma’s MCP server returns 403s to legitimate clients: it admits clients by the
client_namethey send at dynamic registration, which proves nothing. And AWS showed how to protect MCP endpoints at the edge with CloudFront and WAF. - The reminder of why it matters: UpGuard found exposed DBHub MCP servers leaking live databases to the open internet.
The protocol is also getting the long-running pieces it was missing. Upstash explained MCP Tasks and the proposed MCP Events — durable long-running tools and agents that wake up — and Google took the MCP Toolbox Java SDK to 1.0.

From the research: Delivering a Modern API Integration Page with Arazzo
You should not be building integrations anymore. You should be describing them. An integration is two ends and a wire — both ends already publish OpenAPI, and Arazzo is the wire. This paper turns the integrations page from a gallery of connectors into a directory of forkable workflows.
Agents Started Choosing Between Payment Rails
Last week the story was that you can now charge an agent per call. This week the people doing it started comparing notes.
- Shveik built both x402 and MPP into one payment handler and wrote up how the traffic on their pay-per-call services actually split between the two. That is the first post I have seen measuring which rail agents choose when they are offered both.
- MadeOnSol laid out MCP vs x402 vs API subscriptions for agents: MCP connects the agent to tools, x402 pays for an eligible call, a subscription authorizes sustained access. Those are three different contracts, and most providers are going to need to offer more than one.
- On the commerce side, Constructor launched agentic checkout with Stripe, and on-chain, a draft ERC-8183 for agentic commerce proposes escrowed jobs with an evaluator attesting the result.
The common thread with the last section: every one of these rails needs to know which agent is paying. That is the problem I spent the week working on myself.

MCP, Counted Honestly at a New Scale
The wider pull changed the MCP count more than anything else, and almost all of the change is one kind of source. Of 196 titles naming MCP this week, 113 come from three MCP directories the fix brought into view — vinkius.com, neuronto.com and agentalog.com — which publish one auto-generated listing per server, not posts. Four more are PyPI releases. Take those out and there are 79, in a pool of 12,654 posts — about 0.6%. Last week was about 0.85% on a smaller, narrower pool. I am not going to call that a decline; the new coverage reaches a lot of blogs that were never going to write about MCP.
What the posts themselves said:
- The help-centre pattern is now everywhere — Planhat published four pages on MCP plugins in a day, with QuotaPath, Nimble, Testlio and CompanyCam not far behind.
- The launches: Bubble shipped Agent 2 and the Bubble MCP, PagerDuty the Rundeck MCP server, Hashnode an MCP server for managing your blog, and Redis wrote up how it built its docs MCP for agents so agents stop answering from pretraining.
- The “which surface” debate continued: Playwright CLI vs MCP vs Kane CLI, compared on tokens, turns and reliability, Semgrep on MCP giving agents tools while hooks give security control, and GC AI on what it learned building more than twenty agent connectors for legal work. And from the people who generate SDKs for a living, APIMatic asked what SDKs are for, twelve years on.

From My Desk: Know Your Agent, and the End of a Nine-Part Series
Across 12,767 third-party posts, OpenAPI appeared in two titles, both from Scalar, on generating it from ASP.NET Core and from FastAPI. The wider lens did not change that ratio at all.
- Know Your Agent. An agent cannot fill in a signup form, and the form was never really about authentication — it was how a provider found out who it was dealing with. So we shipped the other half of Know Your Agent on APIs.io: an agent that signs up for your API should arrive with a record, every fact graded by how we know it, and two numbers — disclosure and verification — never collapsed into one. That is my answer to the question both sections above keep asking.
- The Kin Score, facet by facet, finished. Nine posts, one facet a business day: this week access clarity, operational transparency, create-or-update ergonomics, open source surface and regulatory posture. Meanwhile Nylas moved into first place on APIs.io at 93.2, past HubSpot, Salesforce and Harness, and I ranked 79 industries by programmability — the opportunity is at the bottom of the table.
- Specifications, from the inside. OpenAPI 3.2, a year on: most API tooling cannot read it, following one in ten providers still publishing Swagger. Overlay 1.2 and the fourteen jobs we already use it for, and an overlay is a layer, not a diff. I sat in on three specification calls in one Thursday, learned what JOSE actually is, and wrote about how we used to ask the clients, and now we unleash the dogs.
- And some opinions. It is called API design, you MCP hustlers. Twenty-four agent bundles and not one MCP server. 984 companies hiring, and 99 of them say OpenAPI. Business capabilities provide the context you need for AI engineering. Who took my API catalog last week, and how much of it. What I learned running the profiling pipeline on gpt-oss-120b.
- The doors into APIs.io. Everything you can do with the APIs.io API — 164 operations — and the 141 tools in the APIs.io MCP server. And a note on this newsletter itself: Commune shipped an API, and our newsletters are moving onto it.
I want to end on the correction I started with, because it is the same lesson as the skills section. My pull had been reading the wrong page for twelve thousand blogs, every weekend, and every signal I had said it was working — the job ran, the posts arrived, the site updated. Nothing was broken except the thing that mattered. An agent loading a skill is in exactly that position: the skill loads, the tools appear, everything works, and nothing tells you whether the thing you are running is the thing that was published.
You only find that out by going and looking.
See you next week.
🔌 APIs.io — Know Your Agent — If you run an API and agents are starting to sign up for it, this is the part of APIs.io I would point you at this week. An agent publishes an A2A card, registers it, and builds a record with us — who operates it, how to reach them, what it is for — with every fact graded verified, attested, declared or absent. When that agent signs up for your API, the record can travel with it, so you get back the thing the signup form used to give you: who you are dealing with.
Start at apis.io/kya to see what a record holds.
Also on the shelf: Change on the Agent Surface
Governing versioning, breaking changes, and deprecation for the MCP tools an agent binds to.
