Dossier
Snyk
Coverage of Snyk in the Nexus archive.
- Minor edits to AI skills can make agents go rogue
Researchers highlight security risks in AI agents where minor modifications to text-based 'skills' can enable prompt injection attacks, allowing malicious actors to bypass safety measures. Studies show 13.4% of skills on platforms like ClawHub contain critical vulnerabilities, including malware and exposed secrets. The issue arises as agents automatically fetch third-party skills, making them susceptible to adversarial manipulation.
- How AI Assistants are Moving the Security Goalposts
AI assistants like OpenClaw are becoming more popular among developers and IT workers but pose significant security risks due to their autonomous capabilities.