AI agent

Experts warn malicious AI skills are hitting more victims than ever — with one family amassing 1.7 million downloads | Daily Reports Online

Share


  • Attackers cloned AI skills, later adding malicious code to steal credentials
  • Zenity Labs found millions of installs and dozens of dangerous skill variants
  • Vercel and Microsoft removed malicious skills, but manual removal is still required

AI skills, instructions that teach AI agents how to do certain tasks and thus extend their capabilities, are increasingly being used in supply chain attacks, researchers have found.


Security experts at Zenity Labs uncovered a credential-stealing campaign on skills.sh, a public registry (essentially an app store) for AI agent skills. In the registry, belonging to Vercel (a cloud platform for web applications), threat actors were cloning existing skills, creating typosquatted lookalikes which, at first, did nothing malicious.



Similar Posts