Skip to main content
Security

820 Malicious Agent Skills and Nobody Noticed

If you are working on agent security and ai security, this is for you.

Take Interest Inc. 5 min read Last reviewed 2026-03-10
ai-security supply-chain agent-safety
Table of contents

Key takeaway

Koi Security found 820+ malicious skills on ClawHub in March 2026, more than doubling from 324 just weeks earlier

Key takeaway

Agent skill marketplaces repeat every mistake app stores made, except agents have deeper system access than mobile apps ever did

Key takeaway

Audit every third-party skill your agents use: who published it, when was it updated, and what permissions does it request

Join the Intelligence Brief

Threat intelligence, agentic vulnerabilities, and engineering frameworks delivered straight to your inbox.

01 / Threat IntelZero-day vulnerabilities and mitigation strategies.
02 / Red TeamQuarterly teardowns of AI infrastructure.
03 / The BlueprintEngineering local-first deterministic computing.

Cite this post

Take Interest Inc. (2026). 820 Malicious Agent Skills and Nobody Noticed. TAKE INTEREST. https://takeinterest.ai/blog/820-malicious-agent-skills-nobody-noticed

Take it with you

Open this post in a machine-readable shape. Send it to your AI, paste it into a research note, or cite it in a doc.