Skill Passed Scanners and Installed on Thousands — AI Security Implications

Colleagues: AIR published a fake skill 'brand-landingpage' that the company says reached ~26,000 agents, incl. corporate accounts (unverified).
Key points:
- Scanners inspect only the skill package; external URLs it references are not analyzed.
- AIR used trust signals (GitHub stars, ads) to drive installs.
- After install the external page was swapped; the skill harvested emails and could have executed more harmful actions with agent privileges.
Recommendations: treat skills as software—verify external URLs, pin versions, apply least privilege, and audit installed skills.
Why it matters: one scanner does not guarantee safety if a skill loads instructions externally.
Which steps do you prioritise in your organisation?
#cybersecurity #AI #supplychainsecurity #agentsecurity

