{"id":1421,"date":"2026-06-23T17:14:53","date_gmt":"2026-06-23T17:14:53","guid":{"rendered":"https:\/\/thedigitalfortress.us\/?p=1421"},"modified":"2026-06-23T17:14:53","modified_gmt":"2026-06-23T17:14:53","slug":"fake-ai-agent-skill-passed-security-scans-and-reportedly-reached-26000-agents","status":"publish","type":"post","link":"https:\/\/thedigitalfortress.us\/?p=1421","title":{"rendered":"Fake AI Agent Skill Passed Security Scans and Reportedly Reached 26,000 Agents"},"content":{"rendered":"<div id=\"articlebody\">\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEgb14v3ddlfpybc15jRbk-cwHI-0S8BAzdp8Ix83L5ZCZ4AB8gCySG7J4tZr4od9q3Jbuic1a4J29VAvRcdSQag_-ju1o9ae9yCcL6XV_jRDVhgd31E5BljiThpXcfHu_gdsmSySY8o0WyjuUoSQ5CGOyKO3cKXVDYeGKa1b1up2VM5ZJE6_PjPNCVOD_M\/s1700-e365\/skills.jpg\" style=\"display: block;  text-align: center; clear: left; float: left;\"><\/a><\/div>\n<p>Security firm\u00a0AIR\u00a0built a fake AI agent skill, pushed it through a popular skill marketplace and an Instagram ad, and says it reached roughly 26,000 agents, including some on corporate accounts.<\/p>\n<p>Every skill security scanner the firm tested it against marked it safe. The payload was harmless by design: it collected the user&#8217;s email address and did nothing else.<\/p>\n<p>The point was to show that none of the signals people lean on to trust a skill caught it: not the scanners, not the GitHub stars, not the open-source reputation.<\/p>\n<p>A skill is a bundle of instructions an agent loads into its own context and follows with roughly the authority of a user prompt. That trust is the whole problem, and it is the reason skill-scanning tools exist in the first place.<\/p>\n<p>The skill, named\u00a0<b>brand-landingpage<\/b>, claimed to build a landing page using Google&#8217;s Stitch design tool, aimed squarely at non-technical users.<\/p>\n<p>To make it look credible, AIR went after two trust signals: GitHub stars and a clean scanner verdict. For the stars, it opened a pull request to a skill marketplace repository with around 36,000 stars and 156 skills.<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/ai-cant-stop-d\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjPEV6-530TOlxG6PjrmdlY623wpBwduZ7t1HV6flcmO5R4q4AmfixDUzW0CrhlvMVNWbhvOIso-UDNTka4W_W9Chrdj_dglwBZwi7DuePM2IMIl-hfUYVIqBXgfpr_2619K8Gptb4LzwJ6gUbi7lWl2M8AFQJsHEaw63Q7tZ6708YGruiHrr0Y2W9YYxLQ\/s728-e100\/ThreatLocker-d.png\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>The pull request was merged after a few days, so the skill inherited the repo&#8217;s count. Then it ran an Instagram ad aimed at marketers, salespeople, and designers, who installed it and put it to work.<\/p>\n<h2>Why the scanners missed it<\/h2>\n<p><a name=\"more\"\/><\/p>\n<p>The scanners AIR tested analyze the package you hand them: the SKILL.md and the files shipped with it. That&#8217;s\u00a0<a href=\"https:\/\/github.com\/cisco-ai-defense\/skill-scanner\">Cisco&#8217;s<\/a>,\u00a0<a href=\"https:\/\/github.com\/nvidia\/skillspector\">NVIDIA&#8217;s<\/a>, and the ones wired into skills.sh.<\/p>\n<p><a href=\"https:\/\/www.air.security\/blog-posts\/the-story-of-skills\" target=\"_blank\">AIR&#8217;s skill<\/a> carried no setup instructions of its own. It told the agent to install the \u00abStitch SDK\u00bb by following the documentation at an external link,\u00a0stitch-design.ai, a domain AIR controls, not Google (the real Stitch lives at\u00a0stitch.withgoogle.com).<\/p>\n<p>At first, the link led to the genuine Stitch docs, so the scanners, seeing a clean package that pointed at a plausible setup page, cleared it. The page the agent would actually fetch and follow sat outside the scan.<\/p>\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEg1aBkfUqO1G782lmRGhP0uU9QlLKjmgTJA1jxNom1jvkr9PmijCryFR-LvoVyumFr6lyR-TMa6wmrhFMJRqXFz1X9DxxA2rYtQD31VgPDNzWFQVXcHdH4tgs32V50Gk97uRsgzQGtsWML270chJhD11stwapvqZLXtftKmfHemZapNBIW6C7QXNj-a3Ck\/s1700-e365\/switch.png\" style=\"display: block;  text-align: center; clear: left; float: left;\"><img decoding=\"async\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEg1aBkfUqO1G782lmRGhP0uU9QlLKjmgTJA1jxNom1jvkr9PmijCryFR-LvoVyumFr6lyR-TMa6wmrhFMJRqXFz1X9DxxA2rYtQD31VgPDNzWFQVXcHdH4tgs32V50Gk97uRsgzQGtsWML270chJhD11stwapvqZLXtftKmfHemZapNBIW6C7QXNj-a3Ck\/s1700-e365\/switch.png\" alt=\"\" border=\"0\" data-original-height=\"1066\" data-original-width=\"1600\"\/><\/a><\/div>\n<p>Once the skill was installed widely, AIR swapped the page behind that link. The new version told the agent to download and run a script.<\/p>\n<p>In the demo, it only mailed the user&#8217;s address back to AIR, which is how the firm counted the agents it reached. A real operator could have used that foothold to read files, move data, or hit internal systems, bounded only by what the agent could reach.<\/p>\n<p>AIR is not the first to show this. Three weeks earlier,\u00a0<a href=\"https:\/\/blog.trailofbits.com\/2026\/06\/03\/the-sorry-state-of-skill-distribution\/\">Trail of Bits<\/a>\u00a0bypassed ClawHub&#8217;s malicious-skill detector, Cisco&#8217;s scanner, and all three scanners wired into skills.sh. Its conclusion was blunt: a scanner checks a fixed package, while an attacker can keep tweaking the payload until it passes.<\/p>\n<p>Real campaigns have used the same\u00a0trick\u00a0for months, keeping the submitted skill clean and hosting the payload on a site the agent only fetches at install.<\/p>\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEiWTVudsjrIN3qorMHITlyY6sPhoEkRbywJl1j5iy_dK2aTTyUEdS0aZXuZJHovooG7ud-DHHrMq7kTn13DLHku7eveORPsXpb8lVi_8F3Thb5g3Q6lUfN49t7zs9CeZR8345gtC5wkuiagZ-Iac2CIPgs5CQuf2qkW8kwFovZx66a5ejk6bqzjtZnDZBo\/s1700-e365\/data.png\" style=\"display: block;  text-align: center; clear: left; float: left;\"><img decoding=\"async\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEiWTVudsjrIN3qorMHITlyY6sPhoEkRbywJl1j5iy_dK2aTTyUEdS0aZXuZJHovooG7ud-DHHrMq7kTn13DLHku7eveORPsXpb8lVi_8F3Thb5g3Q6lUfN49t7zs9CeZR8345gtC5wkuiagZ-Iac2CIPgs5CQuf2qkW8kwFovZx66a5ejk6bqzjtZnDZBo\/s1700-e365\/data.png\" alt=\"\" border=\"0\" data-original-height=\"1437\" data-original-width=\"1894\"\/><\/a><\/div>\n<p>The problem is structural: the scan happens once, but the page a skill points the agent to can be rewritten at any time after. Anthropic&#8217;s own\u00a0<a href=\"https:\/\/platform.claude.com\/docs\/en\/agents-and-tools\/agent-skills\/overview\">docs<\/a>\u00a0already warn that skills fetching external URLs are risky for exactly this reason, since the content can change after the skill is vetted.<\/p>\n<p>Separate\u00a0<a href=\"https:\/\/theweatherreport.ai\/posts\/skill-scanner-disagreement\/\">research this year<\/a>\u00a0found scanners often disagree, because each one judges a skill in isolation, blind to its external links and to what changes after review.<\/p>\n<h2>What to do<\/h2>\n<p>The read for defenders is the same one researchers keep landing on, now with a sharper example behind it. Treat skills as software, not text. Vet what a skill points to, not just what ships inside it.<\/p>\n<p>Most of these add-ons got installed with no review, so the first job is finding what is already running. Route new skills through a single source you control, and re-check them when anything changes, because a clean result at install does not stay clean if the skill phones out to a link someone else can edit.<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/vpn-threat-report-m\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhFlTC7RrRZGiFAgASS0noWSL0qsQGFVp8-Hvuw9yp3X3VKRuTcb5SsPX09wJzrdIM6pu1_5lS4EeZp7Sx4iYBpNJkrGnpr08yyaS1HQ5_5TxaCsP6O0OtHNuOkesn6CbNjao1GPulCJk-uljYMSfMZfBYNrngpe669t7jlRn1FqiEnXhsFD1WVkpaYIVgh\/s728-e100\/ai-d.jpg\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>Pin versions. Hold agents to the least privilege. Assume any external instruction an agent fetches runs with the agent&#8217;s access.<\/p>\n<p>The scale figures come from AIR alone, and they deserve a skeptical read. The firm is launching a managed skill marketplace and closes the write-up, pitching it, so the 26,000 number, the corporate-account detail, and the claim that it could have seized full control of every agent are the company&#8217;s own and are not independently confirmed.<\/p>\n<p>What holds up is the method. The named scanners really do judge only the submitted package, the external-link blind spot is real and has been independently demonstrated, and the trust signals AIR borrowed, stars, and a clean scan are exactly the ones the ecosystem still treats as proof.<\/p>\n<p>The experiment does not expose a new bug so much as it lines up every weak trust signal around agent skills into one run: stars that can be borrowed, a scan that reads a snapshot, and a link that can be rewritten after the check clears.<\/p>\n<p>Whether the real figure is 26,000 or a fraction of it, the gap it walks through is one that defenders still have not closed.<\/p>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>Security firm\u00a0AIR\u00a0built a fake AI agent skill, pushed it through a popular skill marketplace and an Instagram ad, and says it reached roughly 26,000 agents, including some on corporate accounts.&hellip;<\/p>\n","protected":false},"author":1,"featured_media":1422,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[683,335,150,2160,2163,2162,2161,47,2159],"class_list":["post-1421","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-agent","tag-agents","tag-fake","tag-passed","tag-reached","tag-reportedly","tag-scans","tag-security","tag-skill"],"_links":{"self":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/1421","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=1421"}],"version-history":[{"count":0,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/1421\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/media\/1422"}],"wp:attachment":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=1421"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=1421"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=1421"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}