Malicious Skill Packages Easily Bypass AI Agent Marketplace Scanners
AI agent skills can read and write files, execute programs and access external services. If a malicious package is installed from a public marketplace, attackers could exploit the agent's permissions to steal credentials or exfiltrate data. Trail of Bits said skills combine code, documentation and natural-language instructions, potentially confounding both conventional static analysis and LLM-based reviews. Companies should therefore not treat automated scanning as their sole basis for trust. The research disclosed no actual financial losses.
Trail of Bits published tests on June 3, 2026, showing that it bypassed OpenClaw's ClawHub, Cisco's skill-scanner and Vercel's skills.sh integration with Gen, Socket and Snyk. Three of the four malicious skills took less than an hour each to create. In one case, inserting 100,000 line breaks caused the scan to truncate its analysis. The researchers recommended pinning package versions and establishing internal approval processes.
All Coverage
1 original reportsThe Backstory
The history behind this eventNo historical echoes for this signal
Subscribe to Mark Radar Weekly
Every Friday, the week's strongest signals in your inbox. Unsubscribe anytime.