Research · curated 5 Oct 2026

AI Agent Supply Chain Risk: Silent Codebase Exfiltration via Skills

Coverage timeline

5 Oct 2026mitiga.io

Single-source research — first reported, latest, and curated coincide.

Why it matters

Mitiga's skill-exfiltration research shows that casually installing third-party AI agent skills can hand attackers a defender's entire codebase, highlighting an unguarded AI supply-chain attack surface as teams adopt reusable agent behaviors at scale.

Mitiga Labs research demonstrates how a seemingly legitimate AI agent 'skill' — reusable instruction bundles installed via one-click npx commands (e.g. from a 'Moltbook' marketplace) — can silently exfiltrate an entire codebase once an agent installs it without verifying its contents. The write-up introduces a 'Breaking Skills' series exposing supply-chain risk in the emerging AI agent instruction-set ecosystem, with a follow-up on a malicious skill compromising Claude Code via Slack.