The sorry state of skill distribution
blog.trailofbits.com | blog | #ai-security | #supply-chain | #agentic-ai | #malware | #prompt-injection | #static-analysis | #skill-marketplace | #agent-security | #clawhub | #scanner-bypass
Summary
Trail of Bits bypassed ClawHub's malicious-skill detector, Cisco's skill scanner, and all three skills.sh scanners in under an hour, showing static scanning cannot secure agentic skill supply chains.
- Published
- Collected
Skip to content