Anatomy of a Bad Skill
Share
AI coding agents can now install skills. That's great for productivity, but also great for attackers.
In this demo, Chainguard's Patrick Smyth walks through real specimens of malicious agent skills. One hides a data exfiltrating command inside a fake "check for updates" step. Another fetches its actual instructions from a remote URL at runtime, meaning what the agent trusts today can be silently swapped out tomorrow.
Patrick also shows their hardening pipeline in action, automatically diffing upstream vs. hardened skills and flagging real risks like obfuscated commands and excessive permissions before they ever reach your agent.