Snyk finds malware planted inside AI agent "skills"
Snyk reported discovering malware embedded in AI agent skills — the packaged, shareable capability bundles agents install to extend themselves. As skill marketplaces grow, they become a distribution channel for malicious code the same way package registries did. If you're wiring third-party skills into an agent, treat them as untrusted dependencies, not config.