Attack  ·  Glossary

Trojanized AI agent skill

This is a malicious 'skill' or plugin — a packaged set of instructions and code an AI agent can install to gain new abilities — that looks legitimate (sometimes using a typosquatted name copying a popular tool) but secretly steals credentials or data once installed. It is a new twist on software supply-chain attacks, aimed specifically at the growing marketplace of add-ons for AI agents.
One case saw fake skills copying popular tool names rack up 1.7 million installs before being caught — showing how quickly a malicious add-on can spread through an ecosystem with little vetting, putting any organization using third-party agent skills at risk of silent credential theft.
Track this in the live feed See how this plays out in real AI security and governance developments.
Open the feed →