logo

Malicious Coding Agent Skills and the Risk of Dynamic Context

ID: 589d78c3-1ee8-586b-bf9a-001faf4e489f

STIX ID: report--589d78c3-1ee8-586b-bf9a-001faf4e489f

Feed Name: Datadog Security Labs

Threat Score
75/100

Date Published: 2026-05-11

Date Updated: 2026-05-12

...
...

This post documents a supply-chain risk in coding agents where malicious Claude Code skills (e.g., Clawsights) use dynamic-context shell commands (`!` preprocessing) to run commands such as `gh auth token` and exfiltrate credentials before the LLM can inspect the skill, effectively bypassing model-level prompt-injection defenses; the report demonstrates the technique, shows test behavior, and provides detection queries and mitigation recommendations (disable skill shell execution, review .claude/skills in repos and nested folders, require reviews, and monitor runtime telemetry).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.