Snyk finds malware planted inside AI agent "skills"

Snyk reported discovering malware embedded in AI agent skills — the packaged, shareable capability bundles agents install to extend themselves. As skill marketplaces grow, they become a distribution channel for malicious code the same way package registries did. If you're wiring third-party skills into an agent, treat them as untrusted dependencies, not config.

Read the source →

AI engineering practiceDev tooling & infrasnykagent-skillsmalwaresupply-chain

← All signals