Research · curated 5 Jul 2026

The Story of Skills - How We Hijacked 26,000 Agents With One Instagram Ad

Coverage timeline

discovered air.security primary 4 Jul 2026csoonline.com

Single-source research — first reported, latest, and curated coincide.

Why it matters

It shows that static and LLM-based skill scanners can be bypassed by externally-hosted, mutable payloads, exposing enterprises relying on AI agent skill marketplaces to supply-chain compromise.

Security firm AIR demonstrated that a malicious AI agent 'skill' (brand-landingpage) could pass current skill security scanners and reach over 26,000 users via an open-source agents repository and Instagram ads. The skill directed agents to install a fake Stitch SDK from an attacker-controlled domain (stitch-design.ai) that redirected to the real Google Stitch site, evading static SKILL.md analysis and later allowing payload changes.