Evidence · DiggingBeagle record
Agent Skills Are Spreading Hallucinated npx Commands
Aikido researcher Charlie Eriksen reports that the nonexistent npm name react-codeshift appeared in LLM-generated Agent Skills, spread to 237 GitHub repositories, and instructed agents to invoke it through npx. After Eriksen defensively registered an empty package under the name, he observed a persistent 1 to 4 downloads per day and attributed the pattern to agents following the copied skill instructions. Aikido explicitly states that the package was harmless and that no breach occurred.
- Published
- Jan 21, 2026
- Publisher
- Aikido Security
Evidence record
Aikido researcher Charlie Eriksen reports that the nonexistent npm name react-codeshift appeared in LLM-generated Agent Skills, spread to 237 GitHub repositories, and instructed agents to invoke it through npx. After Eriksen defensively registered an empty package under the name, he observed a persistent 1 to 4 downloads per day and attributed the pattern to agents following the copied skill instructions. Aikido explicitly states that the package was harmless and that no breach occurred.
Claim-level citations (3)
- supportsA hallucinated react-codeshift command spread through Agent Skills and reached real npm fetches: Aikido reports that the nonexistent npm identifier react-codeshift appeared in an October 2025 commit adding 47 LLM-generated Agent Skills, with at least two skills instructing agents to invoke it, and that the reference spread to 237 GitHub repositories before defensive registration.
Sections 'Enter react-codeshift' and 'The origin story', including the 237-repository count, commit 65e5cb0, the 47 LLM-generated skills and the affected react-modernization and react-state-management skills.
- supportsA hallucinated react-codeshift command spread through Agent Skills and reached real npm fetches: After defensive registration, Aikido observed a persistent 1 to 4 react-codeshift downloads per day and interpreted the pattern as agents following copied skill instructions and triggering npx resolution; public download telemetry does not independently identify each requester.
Section 'Proof of active execution attempts', including the download telemetry and the researcher's interpretation of the traffic.
- supportsA hallucinated react-codeshift command spread through Agent Skills and reached real npm fetches: The defensively registered react-codeshift package was harmless, and Aikido reports that the episode did not produce a breach or compromised victim.
Section 'Why this matters', where the researcher states that the package is a safe placeholder and that nobody was compromised.