AI-agent skill packages and repository instruction files are emerging as a supply-chain attack vector: attackers can alter natural-language instructions in files such as SKILL.md or AGENTS.md to hijack an agent’s goals and use its existing tools, credentials, filesystem access, and network connectivity. Reported examples include the ClawHavoc campaign, Atomic macOS Stealer distribution through OpenClaw skills, and a malicious ClawHub skill identified by Cisco that exfiltrated data and injected prompts; compromised release pipelines and malicious package releases can also seed this control plane.
The impact depends on the authority granted to the affected agent, particularly where it can execute commands or access secrets without meaningful approval. Organizations should treat agent instructions and skills as privileged, untrusted dependencies: maintain an inventory, review raw source and Unicode content, use vetted internal registries and pinned versions, sandbox agents, constrain credentials and outbound access, and ensure approval prompts disclose the actual command payload and destination. Instruction-file tampering should trigger investigation and restart of potentially compromised agent sessions.

Track how attackers are adapting to this technology.
13 events from the most recent confirmed update back to the earliest known activity.
Jiarui Li and seven co-authors submitted a paper introducing Skill Policy Integrity and SkillShift, a black-box framework for covertly steering LLM-agent decisions through plausible skill-policy edits. In agentic commerce and software-dependency scenarios, SkillShift achieved attacker-favored selection rates of 81.33% and 63.33% while preserving utility and evading evaluated scanners.
Malicious LiteLLM versions appeared on PyPI within days of the Trivy release-pipeline compromise. The incident was contained, with reported impact limited to some leaked API keys.
A compromise of Trivy's release pipeline exposed publishing credentials, creating a software supply-chain risk that could also affect agentic environments reliant on compromised packages.
The public OpenClaw marketplace ClawHub reportedly exceeded 10,000 community-contributed agent skills, expanding the third-party skill supply chain.
Embrace the Red demonstrated that a legitimate agent skill could be invisibly backdoored using Unicode tag characters, causing an agent to execute an arbitrary command when the skill was invoked.
Between January 27 and January 31, the ClawHavoc campaign uploaded 341 malicious skills to the ClawHub marketplace. Koi Security assessed 335 of them as part of one coordinated operation targeting SSH keys, API credentials, cryptocurrency-wallet keys, browser passwords, and .env files; at the campaign's peak, five of ClawHub's seven most-downloaded skills were confirmed malware.
OWASP published a dedicated Agentic Skills Top 10 as the ecosystem faced active attacks and supply-chain risks from malicious skill instructions and bundled code.
Anthropic published the Agent Skills specification as an open standard. Microsoft subsequently adopted Agent Skills within VS Code and GitHub, according to Anthropic product manager Mahesh Murag.
OWASP published its broader Top 10 for Agentic Applications, preceding its later dedicated guidance for agent skills.
Anthropic launched Skills for Claude, introducing reusable skill packages centered on natural-language instructions for agents.
Cisco's AI Threat and Security Research team analyzed the third-party ClawHub skill “What Would Elon Do?” and found nine security issues, including two critical and five high-severity findings. The number-one-ranked skill included a silent curl command to exfiltrate data and a prompt injection intended to bypass assistant safety guidelines.
Trend Micro documented a campaign distributing Atomic macOS Stealer through disguised OpenClaw skills. The skills used professional-looking documentation and a fake password-required setup process to induce malware installation through the agent's trusted role.
Snyk scanned 3,984 skills from ClawHub and skills.sh in its ToxicSkills audit, finding critical-severity issues in 13.4% and at least one flaw of any severity in 1,467 skills (36.8%). It reported that eight of 76 confirmed malicious payloads were still publicly available on ClawHub at the time of reporting.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
3 references tracked. Mallory keeps watching after this page renders.
arxiv.org
Open sourceprompt.security
Open sourcenoma.security
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.