Join us

Skill Issues: How We Discovered Supply Chain Attack Vectors in an AI Agent Skills Marketplace

Skill Issues: How We Discovered Supply Chain Attack Vectors in an AI Agent Skills Marketplace

Orca Security researchers identified four attack primitives in an AI coding-agent skills marketplace: install-count inflation without authentication, security scans at creation and popularity thresholds, same-name overrides without user alerts, and bulk updates without per-skill review or version pinning.

The researchers used three proofs of concept to combine those flaws into bait-and-switch, nested injection, and delayed weaponization attacks. In each case, an attacker could publish malicious Markdown skills, get them through audits, reach users, and execute code on user machines.


Give a Pawfive to this post!


Only registered users can post comments. Please, login or signup.

Start writing about what excites you in tech — connect with developers, grow your voice, and get rewarded.

Join other developers and claim your FAUN.dev() account now!

Avatar

VarBear #SoftwareEngineering

FAUN.dev()

@varbear
Meet Varbear - your friendly companion! Varbear the Bear builds your weekly reading list - one tool, one tutorial, one commit at a time.
Developer Influence
6

Influence

1

Total Hits

156

Posts