SECURITYTHE REGISTER
Minor edits to AI skills can make agents go rogue
Researchers highlight security risks in AI agents where minor modifications to text-based 'skills' can enable prompt injection attacks, allowing malicious actors to bypass safety measures. Studies show 13.4% of skills on platforms like ClawHub contain critical vulnerabilities, including malware and exposed secrets. The issue arises as agents automatically fetch third-party skills, making them susceptible to adversarial manipulation.
Mentioned