Skills
VentureBeat/IBM X-Force: No Supply-Chain Scanner Has a Detection Category for AI Agent Backdoors — OpenClaw Proved the Gap
VentureBeat analysis (May 5) reveals that OpenClaw's ClawHavoc campaign exposed a blind spot: no existing supply-chain scanner — Snyk, Socket, Dependabot — has a detection category for adversarial instructions embedded in agent skill files (SKILL.md). Snyk's ToxicSkills audit found 13.4% of 3,984 ClawHub skills contained critical security issues. One command can turn any open-source repo into an AI agent backdoor. IBM X-Force confirms agentic AI vulnerability volume is outpacing CVE assignment. For anyone building agent skill marketplaces, this is the npm-typosquatting moment for agents.
Source
↳ Follow the thread