Evidence · DiggingBeagle record

ToxicSkills: malicious AI Agent Skills and supply-chain compromise

Snyk scan of 3,984 Agent Skills from ClawHub and skills.sh, distinguishing general security flaws from a HITL-confirmed subset of intentionally malicious payloads used for credential theft, backdoors and exfiltration.

Published
Feb 5, 2026
Source role
primary disclosure

Evidence record

Snyk scan of 3,984 Agent Skills from ClawHub and skills.sh, distinguishing general security flaws from a HITL-confirmed subset of intentionally malicious payloads used for credential theft, backdoors and exfiltration.

Read the original source ↗

Claim-level citations (3)

Cite this record

DiggingBeagle. “ToxicSkills: malicious AI Agent Skills and supply-chain compromise.” Published Feb 5, 2026. https://diggingbeagle.com/sources/toxicskills-malicious-ai-agent-skills-and-supply-chain-compromise/

Citation guidance