CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

SkillCloak Lets Malicious AI Agent Skills Evade Static Scanners with Self-Extracting Packing

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 22

As cited

Copy frozen at (site build).

ai security

SkillCloak Lets Malicious AI Agent Skills Evade Static Scanners with Self-Extracting Packing

Researchers from Hong Kong University of Science and Technology demonstrated that malicious AI agent skills can evade static security scanners through packing techniques. Their most effective evasion method bypassed all tested scanners over 90% of the time, and the team also developed a runtime-based detection approach to identify such threats.

Why it matters: Static scanners are missing most AI agent skill malware when packed with these techniques; practitioners should evaluate runtime detection approaches to catch these threats before execution.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

ai security

SkillCloak Lets Malicious AI Agent Skills Evade Static Scanners with Self-Extracting Packing

No summary had been written when this copy was frozen.

First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

ai security

SkillCloak Lets Malicious AI Agent Skills Evade Static Scanners with Self-Extracting Packing

Researchers at Hong Kong University of Science and Technology demonstrated that malicious skills designed for artificial intelligence (AI) coding agents can evade static security scanners through simple obfuscation techniques, with their strongest method bypassing all tested scanners over 90% of the time. The team also developed a runtime checker capable of detecting most of these evasion attempts.

Why it matters: DevOps and security teams deploying AI coding agents must recognize that static scanning alone is insufficient for validating third-party skills, and runtime monitoring is necessary to catch obfuscated malware that reaches production environments.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary