The Wire.Tracking threats to Agents 312 raw → 45 curated · updated 27 Jun 2026

Incident · curated 27 Jun 2026

Fake AI Agent Skill Passed Security Scans and Reportedly Reached 26,000 Agents

First reported 23 Jun 2026 · 3d ago

Coverage timeline

23 Jun 2026

Single-source incident — first reported, latest, and curated coincide.

It demonstrates that malicious AI agent skills can pass existing security scans and spread widely through marketplaces, posing a real supply-chain risk to enterprise agent deployments.

Security firm AIR built a fake AI agent skill and distributed it via a popular skill marketplace and an Instagram ad, reportedly reaching roughly 26,000 agents including some on corporate accounts. Every skill security scanner tested marked it safe, though the payload was harmless by design and only collected the user's email address.

Why it matters

It demonstrates that malicious AI agent skills can pass existing security scans and spread widely through marketplaces, posing a real supply-chain risk to enterprise agent deployments.

Curated from sources around the web.
Permalinks stay valid even if an incident is later merged.   Feed · Search · API docs · RSS