Evidence · DiggingBeagle record
ToxicSkills: malicious AI Agent Skills and supply-chain compromise
Snyk scan of 3,984 Agent Skills from ClawHub and skills.sh, distinguishing general security flaws from a HITL-confirmed subset of intentionally malicious payloads used for credential theft, backdoors and exfiltration.
- Published
- Feb 5, 2026
- Source role
- primary disclosure
Evidence record
Snyk scan of 3,984 Agent Skills from ClawHub and skills.sh, distinguishing general security flaws from a HITL-confirmed subset of intentionally malicious payloads used for credential theft, backdoors and exfiltration.
Claim-level citations (3)
- supportsMalicious OpenClaw skills abused the agent's inherited local authority: Snyk scanned 3,984 skills and found 534 with at least one critical-level issue and 1,467 with at least one issue of any severity; separately, human-in-the-loop review confirmed 76 intentionally malicious payloads designed for credential theft, backdoor installation or data exfiltration. Snyk's corpus deduplication was keyed by author and skill identity rather than proving that differently republished skill IDs were independent malware families.
Opening study results; findings table; dataset/deduplication discussion; 'Beyond the statistics' HITL-confirmed malicious-payload paragraph
- contextMalicious OpenClaw skills abused the agent's inherited local authority: Unit 42 describes OpenClaw skills as markdown-driven packages with broad local access and documents malicious instructions that leverage the agent's own filesystem, shell, credential-manager or authenticated-session authority rather than requiring a conventional software exploit.
What makes Agent Skills dangerous
- supportsMalicious OpenClaw skills abused the agent's inherited local authority: The Snyk security-issue prevalence, the human-confirmed malicious subset, Unit 42's five later unblocked skills and any marketplace download or listing counts describe different populations; none of those figures is a verified victim-compromise count.
Study population, findings table and HITL-confirmed malicious subset
Cite this record
DiggingBeagle. “ToxicSkills: malicious AI Agent Skills and supply-chain compromise.” Published Feb 5, 2026. https://diggingbeagle.com/sources/toxicskills-malicious-ai-agent-skills-and-supply-chain-compromise/