Security · 1h ago
AI Agent Skills: The New Package Manager Security Nightmare
AI coding tools like Claude and GitHub Copilot now support installing 'skills'—folders of instructions and scripts. GitHub's own docs warn skills are unverified and may contain malicious code. A researcher built a fake CSV formatter skill to demonstrate how hidden scripts could execute without human review.
Meridian48 take
The article rightly flags a serious supply-chain risk, but the real danger is that developers treat skills like npm packages without equivalent vetting.
Read the full reporting
Auditing Agent Skills: A Threat Model for the Next Generation of AI Package Managers →
DEV Community
ai-agentssupply-chain-security