The bottleneck
Agent capability is becoming modular: teams copy SKILL.md files, prompt packs, MCP servers, browser actions, filesystem permissions, and workflow instructions into agents because it feels fast. The hidden risk is operational, not only technical: nobody can explain which agent gained which capability, what data it can touch, whether the skill came from a trusted source, or how to roll it back after a bad run. Non-technical operators do not need a security lecture; they need a one-page decision packet before the change goes live.