As cited
Copy frozen at (site build).
ai security
Malicious AI agent skills can slip past the scanners built to stop them
AI agent skills, small bundles of code and instructions used by AI coding tools, are being distributed through public marketplaces similar to traditional package repositories. Security scanners designed to detect malicious skills have been found to miss threats, and a marketplace has accumulated over 40,000 listed skills within months of the format's emergence.
Why it matters: Developers integrating third-party AI agent skills into their systems face supply chain risk if existing security controls fail to identify malicious or compromised skills before deployment.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
ai security
Malicious AI agent skills can slip past the scanners built to stop them
No summary had been written when this copy was frozen.
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
ai security
Malicious AI agent skills can slip past the scanners built to stop them
Developers use public marketplaces to add agent skills, small bundles of instructions and scripts, to artificial intelligence (AI) coding tools like Claude Code and OpenAI Codex. Malicious skills in these repositories can evade detection systems that are meant to block harmful code before it executes.
Why it matters: Development teams and platform operators should audit third-party AI agent skills before deployment, as current scanning defenses may not catch malicious code disguised in plain-English instructions or obfuscated scripts.
- Source published
- First seen by Cybersecurity Tracker