Fetching from the wire…
Security2026-07-29 · source-backed
arXiv 2607.25619 uses a regex prefilter that lets safe Markdown skill packages bypass the LLM judge entirely, sending only matched snippet windows for flagged files. On SkillsBench (n=1,650, 9.1% malicious) it hits 1.13% FPR and beats two existing tools by 5-6x on AUPRC. The threat is independently confirmed: Snyk's February audit of 3,984 ClawHub and skills.sh skills found 534 with a critical issue and 76 confirmed malicious payloads, 8 still live at publication.
Each link below shares sources, entities, or timing with this story.
The agent skills supply chain is under coordinated attack. Snyk's ToxicSkills audit found 36% of ClawHub's 3,984 skills contain prompt injection payloads, 13.4% have critical malware, and submission rates exploded 10x to 500+/day. This week alone: CVE-2026-2256 (CVSS 9.1) is a...
Microsoft Research dropped a paper that should change how every builder thinks about their agent configuration files. SkillOpt (arXiv 2605.23904) treats a Markdown document as an external parameter of a frozen LLM and applies learning rate, batch, and momentum concepts in text...
Two thirds. Not two thirds of a contrived jailbreak set. Two thirds of realistic malicious issue requests, against the exact three tools most of the people reading this run daily. Ankur Singh, Jinqiu Yang, and Tse-Hsun Chen built IssueTrojanBench across four attack categories...
1. Flip your multi-model pipeline to review-then-generate. Instead of using a reasoning model to plan before code generation, let the specialist generate freely and use reasoning tokens for review. Paper shows 90.2% pass@1 vs 87.2% for the planning pattern. Source 2. Audit you...
The first real supply chain attack on the agent instruction layer landed this week, and it's worse than the early reports suggested. A campaign dubbed ClawHavoc planted 1,184 malicious skills in ClawHub — OpenClaw's official skill marketplace — by embedding adversarial instruc...
Koi Security found 820+ malicious skills on ClawHub (up from 335 in ClawHavoc days ago). Skills use professional docs and innocent names like "solana-wallet-tracker" then install keyloggers (Windows) or Atomic Stealer (macOS). Loaded skills inherit OpenClaw's full system permi...
MindPattern daily
One email a day at 7 AM. Sources and a take on every story. Unsubscribe anytime.