Skip to main content
Security

820 Malicious Agent Skills and Nobody Noticed

Take Interest Inc. · · 5 min read

Field Guide

820 Malicious Agent Skills and Nobody Noticed

Koi Security found 820+ malicious skills on ClawHub, up from 324 weeks earlier. Agent marketplaces are the new attack vector builders aren't watching.

ai-security supply-chain agent-safety

Key takeaway

Koi Security found 820+ malicious skills on ClawHub in March 2026, more than doubling from 324 just weeks earlier

Key takeaway

Agent skill marketplaces repeat every mistake app stores made — except agents have deeper system access than mobile apps ever did

Key takeaway

Audit every third-party skill your agents use: who published it, when was it updated, and what permissions does it request

Join the Intelligence Brief

Threat intelligence, agentic vulnerabilities, and engineering frameworks delivered straight to your inbox.

01 / Threat IntelZero-day vulnerabilities and mitigation strategies.
02 / Red TeamQuarterly teardowns of AI infrastructure.
03 / The BlueprintEngineering local-first deterministic computing.