logo

ClawHub, Cisco, Vercel’s Malicious Skill Detector Bypassed to upload Malicious Skills

ID: 11214a43-8c10-5124-954c-05a0acf39509

STIX ID: report--11214a43-8c10-5124-954c-05a0acf39509

Feed Name: cybersecurityNews.com

Threat Score
55/100

Date Published: 2026-06-05

Date Updated: 2026-06-05

Author: Abinaya

...
...

Trail of Bits research shows that AI skill marketplaces and open-source skill scanners (ClawHub, Cisco, Vercel) can be trivially bypassed using simple obfuscation and packaging techniques—such as newline padding to truncate analysis, embedding precompiled .pyc bytecode, hiding scripts inside document archives, and prompt-injection—that let malicious skills pass automated scans and potentially access environment data; researchers recommend treating public skills as untrusted and adopting supply-chain controls (curated repos, strict access controls, version pinning).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.