Home / Companies / Snyk / Blog / Post Details
Content Deep Dive

Snyk Finds Prompt Injection in 36%, 1467 Malicious Payloads in a ToxicSkills Study of Agent Skills Supply Chain Compromise

Blog post from Snyk

Post Details
Company
Date Published
Author
Luca Beurer-Kellner and Aleksei Kudrinskii and Marco Milanta and Kristian Bonde Nielsen and Hemang Sarkar and Liran Tal
Word Count
3,267
Company Posts That Month
19
Language
English
Hacker News Points
-
Post removed?
No
Summary

The first comprehensive security audit of the AI Agent Skills ecosystem, conducted by Snyk security researchers, unveils significant vulnerabilities involving malware, credential theft, and prompt injection attacks, particularly affecting platforms like OpenClaw, Claude Code, and Cursor. The audit scanned a total of 3,984 skills, discovering that 13.4% contained critical security issues, including malware distribution and exposed secrets, while over a third had some form of security flaw. The research highlights that the Agent Skills ecosystem, characterized by rapid growth and inadequate security measures, poses a substantial risk due to its extensive access to credentials, file systems, and APIs, similar to early software package ecosystems like npm and PyPI. The study identifies a convergence of traditional malware with prompt injection techniques, which manipulate the AI agent's reasoning processes, significantly enhancing the effectiveness of attacks. Snyk's mcp-scan tool, utilized in this research, achieved high accuracy in detecting malicious patterns, emphasizing the urgent need for robust security practices in the evolving Agent Skills domain. The audit also identified eight malicious skills still publicly accessible on ClawHub, urging immediate defensive actions and highlighting the necessity for continuous and adaptive agentic security measures.

Trends Found in this Post
Trend Post Mentions Total Month Mentions Posts Companies MoM
MCP 16 4,186 446 170 +13%
OpenClaw 12 1,515 119 48 +222%
Secrets Management 8 1,524 254 108 +20%
AI Agents 6 4,369 971 249 +0%
Harness engineering 2 124 77 47 +35%
LLM 2 5,987 964 233 +29%
Vector Search 2 2,415 482 157 +17%
AI Guardrails 1 449 167 60 +25%
Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.