AI Governance Institute
← News
Research2026-08-07

1.7M Trojanized AI Skill Installs Expose Agent Marketplace as Active Attack Surface

What happened

Security firm Zenity disclosed a targeted supply chain attack in which threat actors uploaded trojanized skill files to the skills.sh agent marketplace, typosquatting on two legitimate AI services: Paperclip and Browser Use. Between July 11 and August 2, 2026, the malicious skills accumulated over 1.7 million downloads before discovery, as reported by CSO Online. Once deployed, the skills instructed AI agents to install a credential stealer designed to harvest SSH keys, cloud provider credentials, Kubernetes configuration files, and CI runner secrets from developer and agent workspaces. A central finding with direct governance implications is that skill files contain natural language instructions rather than compiled or interpretable code, which prevents standard static analysis tools from flagging malicious content at ingestion. That detection gap means organizations relying on existing software supply chain controls to cover their agent skill ecosystems may have significant unmonitored exposure.

Why it matters

  • ·Existing software supply chain security programs do not extend to agent skill marketplaces without modification: because skill files are written in natural language rather than code, they evade static analysis and code-review tools that enterprises rely on for dependency vetting, leaving intake controls blind to malicious instructions embedded in seemingly benign skills.
  • ·The credentials targeted in this campaign, including SSH keys, cloud provider tokens, Kubernetes configs, and CI runner secrets, are high-value pivot points that allow an attacker to move laterally from a compromised agent workspace into production infrastructure, meaning a single poisoned skill can escalate into a broad enterprise breach.
  • ·With 1.7 million installs accumulated in under four weeks, the velocity of propagation through lightly governed skill marketplaces far outpaces traditional vendor risk review cycles, exposing a timing gap in third-party AI tool intake processes that compliance teams have not yet resolved.

Governance controls affected

What to do now

  • ☐Audit all agent skill and plugin sources currently in use across enterprise agent deployments, mapping each to its originating marketplace and verifying the publisher identity against official vendor registries to catch typosquatted or impersonating packages.
  • ☐Restrict agent skill installation to an approved list maintained through a formal intake workflow, requiring manual review of natural-language instruction content before any skill is permitted in production environments.
  • ☐Rotate all credentials stored in or accessible from developer and agent workspaces that could have been reached by a deployed skill between July 11 and August 2, 2026, prioritizing SSH keys, cloud provider tokens, Kubernetes configs, and CI runner secrets.
  • ☐Update your agent supply chain risk assessment (AGT-019) to explicitly address natural-language skill files as a distinct artifact class requiring review methods beyond static code analysis, such as semantic review or sandboxed execution testing.
  • ☐Implement or verify isolation controls ensuring that agent credential stores are segmented from developer workspaces, so a compromised skill cannot traverse from the agent runtime into broader infrastructure secrets.

What to watch next

Enterprises should monitor whether skills.sh and comparable agent marketplaces introduce publisher verification, code signing, or content integrity mechanisms in response to this incident, since the absence of such controls is structural rather than incidental. The OWASP Top 10 for Large Language Model Applications covers supply chain and plugin integrity risks and is likely to see updated guidance as agent-specific attack patterns become better documented. Regulatory bodies that have begun scrutinizing agentic AI deployments, particularly under the EU Cyber Resilience Act, may treat unvetted skill marketplace usage as a software supply chain risk requiring disclosure or remediation. Teams should also track whether this incident accelerates enforcement attention on agent plugin governance across sectors already under AI oversight obligations.

Related Coverage

Research2026-10-03

Orchestration Framework Flaws Make AI Workflow Pipelines a Primary Attack Target

Research published by Help Net Security finds that agent orchestration frameworks including Flowise and Langflow are among the most actively targeted systems in current vulnerability disclosures. Attackers use prompt injection and manipulated workflow configuration files to reach code execution points inside enterprise AI pipelines. Organizations running agentic workflows need isolation, configuration validation, and red-team coverage at the orchestration layer, not just at the model level.

Research2026-10-01

Akamai: MCP Attack Surface Requires Zero Trust Controls and Machine Identity Governance

Akamai published a research report arguing that the Model Context Protocol (MCP) has become a significant enterprise attack surface. MCP is the standard that lets AI agents connect to external tools and systems. The report finds that malicious MCP servers can manipulate AI agent behavior through prompt injection and cross-server attacks. Akamai calls for organizations to inventory MCP servers, enforce least-privilege permissions, govern machine identities, and monitor autonomous agent activity.

Research2026-09-25

Three Attacks Target AI Keys, LLM APIs, and Provider Access Controls

Security researchers have documented three distinct active threats targeting AI infrastructure: credential-harvesting malware hidden in AI agent packages, a Windows implant that delegates command-and-control decisions to commercial large language models including DeepSeek and Gemini, and nearly 11,000 relay servers routing sanctioned-region traffic to Anthropic, OpenAI, and Google. Each threat exploits a different gap in how enterprises govern their AI dependencies, API credentials, and provider-level access controls. Compliance teams cannot rely on provider-side controls alone to contain any of these risks.