As cited
Copy frozen at (site build).
ai security
Thousands of malicious AI skills found capable of stealing data, running malware
ESET researchers analyzed nearly 900,000 AI skills and identified more than 25,000 suspicious ones capable of stealing data, executing malware, or manipulating agent behavior. AI agents that rely on external skills to browse the web, use tools, and execute commands face expanded attack surfaces through these malicious integrations.
Why it matters: Organizations deploying AI agents with third-party skills need to implement vetting and isolation controls immediately, as malicious skills can compromise data and systems at scale.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
ai security
Thousands of malicious AI skills found capable of stealing data, running malware
No summary had been written when this copy was frozen.
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
ai security
Thousands of malicious AI skills found capable of stealing data, running malware
A review of nearly 900,000 artificial intelligence (AI) skills identified more than 25,000 suspicious skills capable of stealing data, executing malware, or manipulating agent behavior, according to the H1 2026 ESET Threat Report. Malicious skills exploit the broad capabilities AI agents use to browse the web, deploy external tools, and run commands on behalf of users. The discovery expands the understood attack surface for AI-driven systems.
Why it matters: Organizations deploying AI agents or allowing users to install third-party skills face data theft and malware execution risks; security teams should audit and control skill installation policies.
- Source published
- First seen by Cybersecurity Tracker