Fake AI agent skill passed every security scanner and reached ~26,000 agents, including corporate accounts
The Hacker News·high signal
Security firm AIR built a benign-looking malicious agent skill, distributed it through a popular skill marketplace plus an Instagram ad, and reports it reached roughly 26,000 agents — some on corporate accounts — while every skill scanner it tested marked the skill safe. The researchers describe a set of attack primitives that combine to let an attacker create, distribute, and persist malicious skills at scale with minimal friction and limited detection. It is concrete evidence that current agent-skill scanning is not a reliable supply-chain control.