NewsToxicSkills: 36% of ClawHub Skills Contain Malicious ComponentsUC Berkeley·high signalXBlueskyLinkedInCopy linkUC Berkeley study finds 36% of popular AI agent skills on ClawHub marketplace contain data exfiltration, prompt injection, or privilege escalation.SourceSource pageUC Berkeley↳ Follow the threadStack layer / Threat patternHow you lay out your repo changes prompt-injection success: highly modular workspaces measurably lower attack success ratearXiv 2608.14876Stack layer / Threat patternMCP tools that write, not read, went from 27% to 65% of tool use - and measured defenses stop under 30% of attacksarXiv 2608.17275Stack layer / Threat patternSkillWatermark: benign-looking skill descriptions turn agent network traffic into a covert exfiltration channelarXivPolicy dependency / Threat patternDependency Confidence Index Scores PyPI Packages on Nine Trust Factors — and Finds Security Metrics SaturatearXiv 2608.16430Stack layer / ContrastAgents predict their own failure well (0.8847 AUROC) but cannot tell you which collaboration protocol will fix itarXiv 2608.14927Stack layer / ContrastCatastrophic Learning: Poisoned Data Can Block a Continual-Learning Model From Acquiring Knowledge It Has Not Seen YetarXiv 2608.18976Stack layer / ContrastDeliberately mixing low-relevance same-domain items into context improved relevance accuracy by +0.077 - and six production patterns cut tokens 60-70%arXiv 2608.17188Policy dependency / Stack layerCompose agent guardrails as an algebra instead of a rule list: 94.8% of policy-violating events intercepted while keeping 86.9% task completionarXiv 2608.16402