AI agents can now install "skills" - bundled instructions, code, and resources - the same way browsers install extensions. A new study says that convenience comes with a gaping hole.
Researchers built a tool called TrustProbe that traces how skill-provided content flows into an agent's code, from installation to execution. They tested it against 11 open-source AI agent frameworks, eight of which have more than 10,000 GitHub stars, and found 104 distinct taint-style vulnerabilities where untrusted skill content could reach sensitive operations like file access or command execution. When they ran real skills pulled from public hubs such as ClawHub against those same agents, 25.1% of the skill-agent trials actually exercised one of the vulnerable paths. In 15 cases, the researchers went further and turned the flaw into a working exploit with a malicious payload.
The real finding isn't the bug count - it's the trust model itself. Agent frameworks are pulling in skill content with insufficient validation, meaning a skill author doesn't need to be clever, just patient, to get an agent to act on their behalf with the authority a user handed it.
This is the npm supply-chain problem wearing a new costume. Just like malicious packages have slipped into JavaScript's ecosystem for years, AI skill hubs are shaping up to be the next place attackers go shopping, except here the payload isn't just code - it's an agent with your credentials.