Can an agent publish a skill without anyone noticing?
No. publish_skill requires the caller to be a Manager or Super admin, or a platform key that carries the skills:publish scope. The published skill appears in Build & publish with a version, a content hash, and the run or conversation that produced it.
Which company tools can I plug in?
Any MCP server reachable over HTTPS: GitLab, Notion, an internal ticketing system, a document store. You register the URL and its allowed hosts, discover the tools it exposes, and bundle the ones you want. Nothing outside the allow-list can be called from a run.
How do remote tools stay safe?
They are always treated as writes. A run that wants to call one parks until a signed-in user approves it; API keys, personal tokens, and schedules cannot approve on their own. The bearer secret comes from a vault reference, and unregistered hosts are refused before any request leaves Core Hub.
What if a memory is wrong or should not have been shared?
Anyone who can see a shared memory can forget it, and every user can forget or make private their own. Memory never contains result rows or credentials, so the worst case is a stale route, not a leaked value.