OWASP has published a final Top 10 list of security risks for agentic AI skills and introduced the Universal Agentic Skill Format v1.0, warning that malicious skills and supply-chain compromise are the most urgent threats facing enterprise AI agents. The guidance highlights how untrusted external instructions, overprivileged skills, and weak visibility into deployed agents can let attackers abuse legitimate automation paths rather than relying on classic prompt injection alone.
The release follows public demonstrations showing how a single weaponized skill or plugin can compromise agents at scale. Researchers described a campaign in which a malicious skill distributed through an Instagram ad reportedly led to the hijacking of 26,000 agents, while another proof of concept showed an unofficial Claude Code marketplace plugin coercing an AI coding assistant to install a trojanized httpx package from an attacker-controlled source. OWASP and industry practitioners said such attacks can steal credentials, persist through dependency manipulation, and evade detection unless organizations inventory agent usage and can rapidly disable malicious skills across their environments.

Track how attackers are adapting to this technology.
6 events from the most recent confirmed update back to the earliest known activity.
Research published on August 6 reported that Trojanized skills tied to the Paperclip-themed campaign had accumulated more than 300,000 installs each.
In August 2026, OWASP released the final Agentic Skills Top 10 list and the Universal Agentic Skill Format v1.0, identifying Malicious Skills as the top risk and Supply Chain Compromise as the second-highest risk.
During the July 2026 Paperclip-themed attack, automated scanners detected the Trojanized Python packages within hours, while the malicious skills reportedly evaded detection.
In early July 2026, an attacker registered a look-alike domain impersonating the Paperclip agentic AI work platform as part of an attack using Trojanized Python packages and weaponized AI skills to steal credentials and other sensitive information.
Air reported that it manipulated a repository system to give an experimental repository a high star count, and said this affected 26,000 agents within hours.
Prompt Security described a supply-chain attack scenario in which a malicious "Python Dependency Helper" plugin from an unofficial marketplace causes an AI coding assistant to install a trojanized version of the Python library httpx from an attacker-controlled source and persist it in dependency manifests.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
3 references tracked. Mallory keeps watching after this page renders.
darkreading.com
Open sourceair.security
Open sourceprompt.security
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.