AgentsOpenClaw Supply Chain Crisis 800 Malicious Skills ClawHavocTrend Micro·high signalXBlueskyLinkedInCopy link800+ malicious skills on ClawHub (20% of registry). ClawHavoc planted 1184+ skills distributing Atomic Stealer. 135K exposed instances. 15K vulnerable to RCE.SourceSource pageTrend Micro↳ Follow the threadPolicy dependency / Stack layerWebMCP-Phalanx blocks all 80 tool-description injections in a browser agent, then gets bypassed by a malicious tool name called before inspectionarXivStack layer / Threat patternGoogle Cloud Shipped Gemini Enterprise for Financial Services With 50 Skills, 13 Connectors and a Partner Agent MarketplaceGoogle Cloud Blog (corroborated by PRNewswire, 2026-08-25 12:00)Stack layer / Threat patternTrojanized pantheon-agents wheels on PyPI ship a Bun-based credential stealer, GitHub source untouchedGitHub Advisory DatabaseStack layer / Threat patternSkillShield defends coding agents from the system prompt alone, matching Llama Guard 3 with no runtime classifierarXivPolicy dependency / Threat patternBorrowed Authority: Agent Skills Carry No Typed Way to Reject a Permission Claim, and Edge Skillguard Rejects 60/60 AttacksarXiv 2608.25091Policy dependency / Stack layerAttnlocate treats prompt injection as an object detection problem inside the attention matrix, hitting 0.934 TPR at 0.067 FPRarXivPolicy dependency / Stack layerCherry Studio v2.0.9 unifies tool approval into one declarative policy and lets the provider catalog hot-update without an app releaseGitHubPolicy dependency / Stack layerA controlled ablation on a production science agent finds the model choice dominates topology and prompting, and a PPO policy nearly matches it for freearXiv