The sorry state of skill distribution
Summary
Public marketplaces for AI skills (specialized add-ons that extend AI agent capabilities) are being flooded with malicious skills that steal passwords and data. Security companies have released skill scanners to detect these threats, but researchers found that these scanners are easy to bypass, sometimes in under an hour, because they rely on static detection methods that attackers can repeatedly modify to evade.
Classification
Affected Vendors
Related Issues
Original source: https://blog.trailofbits.com/2026/06/03/the-sorry-state-of-skill-distribution/
First tracked: June 3, 2026 at 08:00 AM
Classified by LLM (prompt v3) · confidence: 92%