logo

Fake AI Agent Skill Passed Security Scans and Reportedly Reached 26,000 Agents

ID: 8f62b787-68c9-5419-b2f2-8b6b12fe5be6

STIX ID: report--8f62b787-68c9-5419-b2f2-8b6b12fe5be6

Feed Name: The Hacker News

Threat Score
60/100

Date Published: 2026-06-23

Date Updated: 2026-06-24

Author: [email protected] (The Hacker News)

...
...

AIR built a fake AI agent skill that inherited marketplace trust signals and passed several skill scanners by pointing installers to external documentation it controlled; after the skill was widely installed the external page was swapped to deliver a script (in the demo it only exfiltrated email addresses). The experiment shows a structural weakness in skill vetting—scanners inspect a snapshot but external URLs can be rewritten post-approval—allowing attackers to manipulate trust signals and potentially achieve broad, high-impact access if weaponized, though the scale and full impact claims are unverified.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.