Research · curated 5 Oct 2026
AI Agent Supply Chain Risk: Silent Codebase Exfiltration via Skills
First reported mitiga.io
Coverage timeline
Single-source research — first reported, latest, and curated coincide.
Why it matters
Mitiga's skill-exfiltration research shows that casually installing third-party AI agent skills can hand attackers a defender's entire codebase, highlighting an unguarded AI supply-chain attack surface as teams adopt reusable agent behaviors at scale.
Mitiga Labs research demonstrates how a seemingly legitimate AI agent 'skill' — reusable instruction bundles installed via one-click npx commands (e.g. from a 'Moltbook' marketplace) — can silently exfiltrate an entire codebase once an agent installs it without verifying its contents. The write-up introduces a 'Breaking Skills' series exposing supply-chain risk in the emerging AI agent instruction-set ecosystem, with a follow-up on a malicious skill compromising Claude Code via Slack.