Security · 3h ago
Fake AI Agent Skill Bypasses Security Scans, Reaches 26,000 Agents
Security firm AIR created a fake AI agent skill that passed all tested security scanners and reached roughly 26,000 agents, including corporate accounts, via a popular skill marketplace and Instagram ad. The skill collected user emails but was otherwise harmless, designed to expose vulnerabilities in AI agent supply chains. The firm warns that a malicious payload could have caused significant damage.
Meridian48 take
The demonstration underscores a critical blind spot in AI agent security: current scanning tools are ineffective against malicious skills, leaving enterprises exposed.
Read the full reporting
Fake AI Agent Skill Passed Security Scans and Reportedly Reached 26,000 Agents →
The Hacker News
ai-agent-securitysupply-chain-attack