Researchers at the Hong Kong University of Science and Technology reported that third-party skills for LLM coding agents can be turned into malware that slips past current marketplace screening. In a paper titled "Cloak and Detonate: Scanner Evasion and Dynamic Detection of Agent Skill Malware," they showed that their SkillCloak framework preserves malicious behavior while changing how payloads appear to static scanners, using structural obfuscation and self-extracting skill packing. Testing on 1,613 malicious skills from ClawHub found that self-extracting packing bypassed all eight evaluated scanners more than 90% of the time, while structural obfuscation also defeated most tools at high rates.
The researchers said the findings expose a broader trust gap in AI-agent ecosystems because harmful behavior often appears only during execution, not during static review. To counter that weakness, they introduced SkillDetonate, a sandboxed runtime auditing system that monitors operating-system-level behavior and tracks sensitive data flows across files, processes, network activity, and agent context. In controlled tests, SkillDetonate detected 97% of attacks at a 2% false-positive rate and maintained 87% detection on real-world malicious skills, reinforcing calls for runtime behavioral checks alongside marketplace scanning for agent skills and related tooling.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
The same research introduced SkillDetonate, a sandboxed behavioral auditing system for agent skills that monitors OS-level behavior and information flows at runtime. The paper reports 97% attack detection at a 2% false-positive rate and 87% detection on real-world malicious skills.
Researchers from the Hong Kong University of Science and Technology described SkillCloak, a framework that preserves malicious agent-skill behavior while using structural obfuscation and self-extracting packing to evade static detection. In reported testing, self-extracting packing bypassed all eight evaluated scanners more than 90% of the time.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
helpnetsecurity.com
Open sourcecybersecuritynews.com
Open sourcethehackernews.com
Open sourcearxiv.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.