Fake AI Agent Skill Passed Security Scans and Reportedly Reached 26,000 Agents
A security firm created a fake AI agent skill that passed security scans and reportedly reached 26,000 agents. The skill was designed to collect user email addresses and demonstrated vulnerabilities in skill-scanning tools.
Intelligence analysis by Llama 3.3 70B

The fake AI agent skill was able to bypass security scans by hosting its payload on an external link, which could be rewritten after the skill was vetted. This highlights the need for defenders to treat skills as software, not text, and to vet what a skill points to, not just what ships inside it.
Imagine you have a robot that can do tasks for you, but you need to give it instructions on what to do. These instructions are like recipes that the robot follows. But what if someone gave the robot a fake recipe that looked real, but actually did something bad? That's kind of what happened in this experiment, where a fake AI agent skill was able to bypass security checks and reach a lot of robots.
Analysis
The Vulnerability of Skill-Scanning Tools
The experiment conducted by the security firm AIR highlights the vulnerability of skill-scanning tools to bypassing. The firm created a fake AI agent skill that passed security scans and reportedly reached 26,000 agents, including some on corporate accounts. The skill was designed to collect user email addresses and demonstrated that skill-scanning tools can be bypassed by hosting the payload on an external link, which could be rewritten after the skill was vetted.
The vulnerability of skill-scanning tools is a significant concern for the security of enterprise systems. These tools are designed to detect and prevent malicious skills from being installed, but the experiment shows that they can be bypassed. This means that defenders need to be more vigilant and take additional steps to ensure the safety of their systems.
The Limitations of Trust Signals
The experiment also highlights the limitations of trust signals such as GitHub stars and clean scanner verdicts. The fake AI agent skill was able to inherit the GitHub stars of a reputable repository, and the clean scanner verdicts gave it a false sense of security. However, these trust signals are not enough to ensure the safety of a skill, and defenders need to look beyond them to ensure the security of their systems.
The Need for a More Comprehensive Approach
The experiment demonstrates the need for a more comprehensive approach to ensuring the security of AI agents and the skills they use. Defenders need to treat skills as software, not text, and vet what a skill points to, not just what ships inside it. This means that defenders need to be more proactive and take a more holistic approach to security, rather than relying on trust signals and skill-scanning tools alone.
The firm's findings are not new, and similar vulnerabilities have been demonstrated in the past. However, the experiment provides a sharper example of the risks and highlights the need for defenders to be more vigilant. The scale figures reported by the firm, including the number of agents reached and the corporate accounts affected, deserve a skeptical read, but the method used to bypass the skill-scanning tools is real and has been independently demonstrated.
The Importance of Defender Vigilance
The experiment emphasizes the importance of defender vigilance in ensuring the security of AI agents and the skills they use. Defenders need to be aware of the limitations of trust signals and skill-scanning tools and take additional steps to ensure the safety of their systems. This includes routing new skills through a single source, re-checking them when anything changes, and assuming that any external instruction an agent fetches runs with the agent's access.
The firm's findings have significant implications for the security of enterprise systems and the trust that users place in AI agents. The experiment demonstrates that skill-scanning tools can be bypassed, and that trust signals are not enough to ensure the safety of a skill. Defenders need to be more proactive and take a more holistic approach to security, rather than relying on trust signals and skill-scanning tools alone.
Key points
- A fake AI agent skill was able to bypass security scans and reach 26,000 agents
- The skill was designed to collect user email addresses and demonstrated vulnerabilities in skill-scanning tools
- Trust signals such as GitHub stars and clean scanner verdicts are not enough to ensure the safety of a skill
- Defenders need to treat skills as software, not text, and vet what a skill points to, not just what ships inside it
The experiment highlights the need for defenders to be more vigilant and take additional steps to ensure the safety of their systems. By being more proactive and taking a more holistic approach to security, defenders can reduce the risk of malicious skills being installed and protect their systems from potential threats. Additionally, the development of more advanced skill-scanning tools and the implementation of more robust security measures can help to prevent similar vulnerabilities in the future.
The experiment demonstrates the vulnerability of skill-scanning tools and the limitations of trust signals, which could lead to a loss of trust in AI agents and the skills they use. If defenders do not take additional steps to ensure the safety of their systems, the risk of malicious skills being installed could increase, potentially leading to significant security breaches and financial losses. Furthermore, the ease with which the fake AI agent skill was able to bypass security checks could embolden malicious actors to launch more sophisticated attacks.



