Solutions  ·  2026-10-04

Zenity Labs launches AI Total — free 'detonation chamber' that runs untrusted AI agent skills in a sandbox

SolutionsMedium impactGlobal
On Oct 2, 2026, Zenity Labs publicly launched AI Total (aitotal.io), a free service that executes an AI agent skill in a sandbox with planted credentials and sensitive files (a 'Detonation Chamber'), then reports actual behavior — domains contacted, packages pulled, files touched, commands run — instead of a static risk score. Pre-launch detonation of thousands of public skills surfaced a credential-stealing campaign reaching ~1.7M installs and skills that instruct agents to download/run attacker files.
Static skill scanning misses payloads that arrive only at runtime; AI Total applies malware-style behavioral analysis to the fast-growing, least-inspected dependency layer (Claude Code/OpenClaw skills). Free access gives the whole ecosystem a routine 'detonate before install' check, with extensions planned deeper into the AI supply chain.
Developers and agent-platform builders adding community skills, plus security teams approving skills org-wide, should run skills through AI Total before deployment; research teams can use it to hunt new registry-based techniques.
Zenity Blog — AI Total
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →