AI Agent Supply Chain Risk: Silent Codebase Exfiltration via Skills
ID: 9a75b4b6-0e4e-5bf7-82c4-b8007285cb69
STIX ID: report--9a75b4b6-0e4e-5bf7-82c4-b8007285cb69
Feed Name: Mitiga
Mitiga Labs demonstrates a proof-of-concept supply-chain attack where a seemingly legitimate AI agent "Testing" skill—when installed into agents like Cursor—uses silent instructions and a weaponized "Definition of Done" to non-interactively copy a local repository, add an attacker remote, push the code to a public branch, and open a signed PR; the report documents the attack flow, shows that audit logs can remain empty, assesses large-scale impact to developer skill ecosystems, and recommends controls such as monitoring skill installations, reviewing instruction logic, and detecting silencing behaviors.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
