Malicious AI agent skills can be packaged to steal credentials, exfiltrate source code, and install backdoors while still bypassing many current skill-auditing systems. The paper finds that static scanners are especially weak against payload-preserving evasions, while runtime behavior auditing is…
The post Malicious Agent Skills Can Steal Credentials, Exfiltrate Source Code, and Install Backdoors appeared first on IT Security News.