Tenable CyberAgents Exchange
by Tenable, Inc.
A free, vendor-neutral registry of security AI agents, skills, MCP servers and playbooks
CyberAgents Exchange is a free, open-source registry where security teams publish and pick up AI agents, skills, MCP servers and multi-agent playbooks built for defensive work. Launched by Tenable in August 2026 with SentinelOne and Recorded Future as founding contributors, it exists so security organisations stop rebuilding the same detection and triage agents in isolation.
Tenable launched the CyberAgents Exchange on 6 August 2026 as an open-source, cybersecurity-native registry for AI agents, skills, Model Context Protocol servers and multi-agent playbooks. It is browsable without an account across four categories, carries contributor leaderboards and badges, and is free to use with no fees for listing or accessing components. Each listing exposes code-level visibility — who built it, when, and its peer-support status — so a security team can judge suitability before adopting. Founding contributors are SentinelOne, which supplied agents, and Recorded Future, which contributed threat-intelligence integration; following Tenable's SWARM build event at Black Hat USA 2026 the Exchange holds more than 100 community-submitted components. The explicit goal is to stop security teams duplicating work and to avoid vendor lock-in on agentic defence tooling. On 3 September 2026 Tenable announced the Exchange AI Inspector, built with OpenAI, which adds the missing trust layer: a three-part security review combining frontier assessment using OpenAI GPT cyber models, skills inspection powered by Tenable One AI Exposure, and expert review by Tenable researchers, with availability expected in September 2026. The collaboration came out of Tenable's participation in the OpenAI Daybreak Defense Network. Tenable itself was founded in 2002, is headquartered in Columbia, Maryland, trades on NASDAQ as TENB, and reported roughly $1.04 billion trailing-twelve-month revenue with about 44,000 customers and 2,353 employees as of July 2026. Buyers should read the Exchange as a distribution and trust layer rather than a runtime — it lists components, it does not execute or orchestrate them.
The SOC or detection-engineering lead whose team is writing its own MCP servers and triage agents from scratch, and who wants a vetted starting point rather than a single vendor's closed agent marketplace.
A free, code-visible catalogue of security-specific agents, skills and MCP servers, with a Tenable/OpenAI security review arriving to vet them before enterprise deployment.
At a Glance
- Category
- Governance & Security
- Pricing
- Free
- Target Market
- CISOs, SOC Managers, Detection Engineers, Security Architects, Threat Intelligence Leads
- Deployment
- Cloud-only, Open-source
- Founded
- 2002
- Headquarters
- Columbia, Maryland, United States
- Team Size
- 500+
- Customers
- 100+ community-submitted components listed; Tenable serves roughly 44,000 customers company-wide
Key Features
- ✓Four-category registry
Catalogues AI agents, skills, MCP servers and multi-agent playbooks in one place so security teams find the right unit of reuse
- ✓Open-source and free to use
No fees for listing or accessing components, and no account required to browse, which removes procurement friction from evaluation
- ✓Code-level provenance
Each listing shows who created a component, when, and its peer-support status so teams can judge suitability before adopting
- ✓Exchange AI Inspector
Three-stage security review using OpenAI GPT cyber models, Tenable One AI Exposure skills inspection and Tenable researcher review
- ✓Vendor-neutral contribution model
SentinelOne and Recorded Future contributed as founding members, so listings are not restricted to one vendor's ecosystem
- ✓Community leaderboards and badges
Contributor recognition including Founding Contributor and SWARM awards, giving buyers a rough signal of who maintains what
Use Cases
- •Bootstrapping a SOC agent programme
A team with no agents in production installs a community triage agent and adapts it rather than starting from an empty repository
- •Sourcing security MCP servers
Engineers find MCP servers that expose scanners and threat intel to agents without writing and maintaining each integration
- •Vetting a community agent before deployment
Security architects run a candidate through Exchange AI Inspector before granting it access to production security telemetry
- •Publishing an internal agent externally
A detection team lists a playbook it already runs, gets peer review and stops maintaining it entirely alone
- •Avoiding single-vendor agent lock-in
Teams assemble defensive workflows from components across several vendors rather than committing to one closed marketplace
Ideal For
Best For
- ✓SOC and detection-engineering teams sourcing ready-made triage, enrichment and investigation agents instead of building each one
- ✓Finding cybersecurity-specific MCP servers that expose security tooling to an agent, rather than general-purpose MCP catalogues
- ✓Publishing internally built security agents and skills to a neutral registry instead of a single vendor's marketplace
- ✓Evaluating multi-agent playbooks that chain several components into a defensive workflow
- ✓Security architects who want code-level visibility into an agent's provenance before it touches production telemetry
Not Ideal For
- ✗Teams that need vendor-supported, SLA-backed and warranted components — these are community contributions with no support commitment
- ✗Non-security AI use cases: the registry is scoped to defensive cybersecurity work and has nothing for general enterprise agents
- ✗Organisations whose policy forbids community-maintained code in a security pipeline, particularly before Exchange AI Inspector is generally available
- ✗Buyers looking for a managed runtime or orchestrator — this is a registry, so you still bring your own agent framework and execution platform
Deployment
Market & Ratings
100+ community-submitted components listed; Tenable serves roughly 44,000 customers company-wide
Market Analysis
Pros
- ✓Free and open, so evaluating it costs nothing and carries no procurement overhead
- ✓Cybersecurity-native scope means listings are relevant to a SOC in a way that general MCP catalogues are not
- ✓Code-level provenance on each listing lets teams judge a component before adopting it
- ✓Multi-vendor founding contributions (SentinelOne, Recorded Future) support the neutrality claim rather than just asserting it
Cons
- ✗It launched in August 2026 with unvetted community submissions; Exchange AI Inspector, the security review layer, was still only 'expected' in September 2026 at the time of writing
- ✗Free registry with no SLA, support commitment or warranty on any listed component — remediation of a broken or malicious agent is on you
- ✗Neutrality is asserted, not governed: there is no foundation or independent steering body, and Tenable controls the platform
- ✗No independent review corpus exists — nothing on G2, Capterra or TrustRadius, no Hacker News discussion, and most coverage so far is syndicated press release
- ✗It is a catalogue, not a runtime: adopting a component still requires your own agent framework, execution environment and security review
Pricing
CyberAgents Exchange
$0
- ✓Free to browse, publish and install
- ✓No listing or access fees
- ✓No account required to browse
- ✓Open-source components across agents, skills, MCP servers and playbooks
The Exchange itself is free with no fees for listing or accessing components, and Tenable publishes no price for it. The one commercial dependency to check in a buying conversation is Exchange AI Inspector: its skills-inspection stage is powered by Tenable One AI Exposure, Tenable's quote-priced exposure-management platform, and Tenable has not publicly stated whether reading Inspector results requires that licence. Budget accordingly — the registry is free, the vetting layer's licensing terms are not yet disclosed.
Security & Compliance
Sources
This page was written from 6 sources, 5 on domains other than exchange.tenable.com.
- 1.exchange.tenable.com — exchange.tenable.comvendor
- 2.tenable.com — tenable uses openai gpt cyber models to help defenders inspe
- 3.securitybrief.com.au — tenable launches free cyberagents exchange for ai security
- 4.citybiz.co — tenable openai launch security review for community built ai
- 5.globenewswire.com — tenable uses open ai gpt cyber models to help defenders insp
- 6.en.wikipedia.org — Tenable, Inc.
Stay Ahead of the Curve
Weekly enterprise AI insights for technology leaders. No spam, no vendor pitches—unsubscribe anytime.
SubscribeRelated Products
SCALR AI
A licence-free multi-agent SOC workbench that runs in your own Azure tenant
Kosmoy
A self-hosted AI control plane: inventory, gateway, observability and agent sandboxing
RadarFirst
Compliance agents that prepare the work — people still make every regulatory decision
Lema
Agentic third-party risk management — treat vendor risk as a security problem, not a checklist