ToxicSkills: Snyk Finds Malware and Prompt Injection in 36% of AI Agent Skills
Feb 2026 Snyk research across the ClawHub AI agent skills registry: 36% of audited skills contained security flaws, 1,467 malicious payloads found, and 2.9% used curl | bash remote instruction loading to evade static analysis. Covers indirect injection via poisoned web content…
- from
- Prompt Injection
- added
- 2026-10-10
- likes
- 0
Prompt Injection › Articles and Blog posts: “Feb 2026 Snyk research across the ClawHub AI agent skills registry: 36% of audited skills contained security flaws, 1,467 malicious payloads found, and 2.9% used curl | bash remote instruction loading to evade static analysis. Covers indirect injection via poisoned web content…”