[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"branding":3,"analytics":7,"article-researchers-find-ai-agent-skills-are-a-security-backdoor":10,"sections":40},{"siteName":4,"siteTagline":5,"publisherName":4,"contactEmail":6},"The Revision","Tech news, decoded.","editor@therevision.news",{"gaMeasurementId":8,"adsenseClientId":9},"G-ZW2MV82GYR","ca-pub-8533917693782264",{"article":11},{"id":12,"slug":13,"title":14,"dek":15,"body_md":16,"tags_json":17,"published_at":18,"created_at":19,"updated_at":20,"status":21,"review_note":22,"review_notes":23,"image_url":22,"persona_id":22,"persona_name":22,"section":30,"tags":31,"sources":35,"feedback":39,"feedback_at":22,"cost_usd":39,"total_tokens":39},9108,"researchers-find-ai-agent-skills-are-a-security-backdoor","Researchers Find AI Agent Skills Are a Security Backdoor","A new study found that 25.1% of real-world AI agent skill trials reached sensitive operations, and researchers turned 15 flaws into working exploits.","AI agents can now install \"skills\" - bundled instructions, code, and resources - the same way browsers install extensions. A new study says that convenience comes with a gaping hole.\n\nResearchers built a tool called TrustProbe that traces how skill-provided content flows into an agent's code, from installation to execution. They tested it against 11 open-source AI agent frameworks, eight of which have more than 10,000 GitHub stars, and found 104 distinct taint-style vulnerabilities where untrusted skill content could reach sensitive operations like file access or command execution. When they ran real skills pulled from public hubs such as ClawHub against those same agents, 25.1% of the skill-agent trials actually exercised one of the vulnerable paths. In 15 cases, the researchers went further and turned the flaw into a working exploit with a malicious payload.\n\nThe real finding isn't the bug count - it's the trust model itself. Agent frameworks are pulling in skill content with insufficient validation, meaning a skill author doesn't need to be clever, just patient, to get an agent to act on their behalf with the authority a user handed it.\n\nThis is the npm supply-chain problem wearing a new costume. Just like malicious packages have slipped into JavaScript's ecosystem for years, AI skill hubs are shaping up to be the next place attackers go shopping, except here the payload isn't just code - it's an agent with your credentials.","[\"ai-agents\",\"security\",\"vulnerabilities\",\"llm-agents\"]","2026-10-01T04:00:00.000Z","2026-10-01T20:21:00.549Z","2026-10-01T20:21:06.696Z","published",null,[24],{"id":25,"reviewer":26,"round":27,"reason":28,"status":29},"editor-r1","editor",1,"The dek claims 'a quarter of tested AI agent skills can reach sensitive operations,' but the body's actual figure (25.1%) measures the share of skill-agent trials that exercised a vulnerable path, not the share of skills themselves — rewrite the dek to accurately reflect that it's trials\u002Fattempts, not a quarter of all tested skills.","resolved","security",[32,30,33,34],"ai-agents","vulnerabilities","llm-agents",[36],{"name":37,"url":38},"arXiv cs.AI","https:\u002F\u002Farxiv.org\u002Fabs\u002F2609.39065",0,{"sections":41},[42,46,49,53,58,63,67,72,77,81,86,91,96,101],{"name":43,"slug":44,"count":45,"latest_published_at":18},"AI","ai",5572,{"name":47,"slug":30,"count":48,"latest_published_at":18},"Security",815,{"name":50,"slug":51,"count":52,"latest_published_at":18},"Policy","policy",430,{"name":54,"slug":55,"count":56,"latest_published_at":57},"Deals","deals",298,"2026-09-30T21:00:26.000Z",{"name":59,"slug":60,"count":61,"latest_published_at":62},"Hardware","hardware",196,"2026-09-30T13:00:00.000Z",{"name":64,"slug":65,"count":66,"latest_published_at":18},"Science","science",163,{"name":68,"slug":69,"count":70,"latest_published_at":71},"Consumer Tech","consumer-tech",149,"2026-09-30T22:57:11.000Z",{"name":73,"slug":74,"count":75,"latest_published_at":76},"Dev Tools","dev-tools",93,"2026-10-01T02:30:48.000Z",{"name":78,"slug":79,"count":75,"latest_published_at":80},"Software","software","2026-09-30T21:41:11.000Z",{"name":82,"slug":83,"count":84,"latest_published_at":85},"Startups","startups",84,"2026-09-30T20:39:09.000Z",{"name":87,"slug":88,"count":89,"latest_published_at":90},"Gaming","gaming",51,"2026-09-30T16:24:30.000Z",{"name":92,"slug":93,"count":94,"latest_published_at":95},"General","general",50,"2026-09-30T21:37:54.000Z",{"name":97,"slug":98,"count":99,"latest_published_at":100},"Reviews","reviews",31,"2026-09-28T14:31:34.000Z",{"name":102,"slug":103,"count":104,"latest_published_at":105},"How-To","how-to",6,"2026-06-16T09:00:00.000Z"]