Solutions  ·  2026-08-17

Zenity Labs launches AI Total, a free dynamic-analysis threat-intel service for AI agent skills

SolutionsMedium impactGlobal
At Black Hat USA 2026 (presented/published Aug 10, 2026), Zenity Labs disclosed a large-scale malicious AI agent 'skills' supply-chain problem (some malicious skills had 250k+ installs) and launched AI Total, a free service that executes submitted agent skills inside a sandboxed 'Agent Detonation Chamber' seeded with bait credentials/files to observe real runtime behavior rather than relying on static code/instruction analysis.
AI agent skill marketplaces (Claude Code, OpenClaw, etc.) are an emerging and largely unmonitored supply-chain attack surface; a free, vendor-neutral dynamic-analysis verdict service lowers the barrier for defenders and researchers to vet third-party skills before granting them agent execution rights.
Security teams and AI platform owners allowing installation of third-party AI agent skills/plugins should adopt dynamic vetting (e.g., AI Total) now, alongside existing static scanning, before permitting skill installs in production agent environments.
Portal ERPCSO Online
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →