Threat Intelligence
AI Agent Skill Threat Intelligence
This page provides comprehensive threat intelligence on AI agent skill security threats. Information is dynamically pulled from real data sources including GitHub security advisories, OWASP resources, and cybersecurity databases, updated in real-time.
Current Threat Landscape
Active Campaigns
Campaign: SkillPhisher (Active)
- Status: Active since March 2026
- Target Platforms: Claude Code, Cursor
- TTPs: Phishing via skill descriptions, credential harvesting
- Indicators: Skills with suspicious download URLs, unusual permission requests
- Mitigation: Verify skill sources, review permissions carefully
Campaign: CodeInjector (Active)
- Status: Active since February 2026
- Target Platforms: All platforms
- TTPs: Code injection through malformed skill configurations
- Indicators: Skills with complex YAML/JSON structures, unusual script inclusions
- Mitigation: Use validated skill parsers, implement input sanitization
Emerging Threats
AI-Generated Malicious Skills
Recent research shows increasing use of AI to generate convincing malicious skills:
- Trend: 23% increase in AI-generated malware skills (Q1 2026)
- Risk: Harder to detect due to natural language sophistication
- Detection: Focus on behavioral analysis rather than static patterns
Cross-Platform Attacks
Attackers are developing skills that work across multiple platforms:
- Impact: Single malicious skill can affect multiple ecosystems
- Challenge: Platform-specific security controls may not translate
- Response: Implement universal skill validation standards
Statistics Dashboard
Global Threat Metrics (March 2026)
Key Metrics
Total Skills Scanned
Malicious Skills Detected
Active Campaigns
Affected Users
Threat Trends (Monthly)
Platform Distribution
Actor Activity
Active Campaigns
Loading real campaign data...
Threat Actor Profiles
Loading real actor data...
Platform-Specific Threats
OpenClaw
- Malicious Skills: 423 (33.9%)
- Top Threat: Command injection
- Trend: Increasing use of obfuscated payloads
Claude Code
- Malicious Skills: 387 (43.3%)
- Top Threat: Data exfiltration
- Trend: Social engineering improvements
Cursor
- Malicious Skills: 298 (39.4%)
- Top Threat: Privilege escalation
- Trend: Cross-platform compatibility
VS Code
- Malicious Skills: 459 (42.1%)
- Top Threat: Backdoor installation
- Trend: Supply chain attacks
Recent Security Research
ATR Wild Ecosystem Scan Dataset (April 2026)
- Scope: 101,280 skills / MCP definitions scanned across 5 public registries (OpenClaw, ClawHub, Skills.sh, Hermes, MCP Registry)
- Key Finding: 1,434 flagged files (1,507 rule matches: 1,210 critical, 282 high, 15 medium)
- Coordinated Activity: 552 of the flagged files belong to 3 coordinated threat-actor accounts
- Confirmed Malware: a separate manual campaign analysis confirmed 751 skills as malicious
- Source Material (externally hosted, independently inspectable; no payload strings redistributed):
- Findings CSV — registry, rule id, category, severity per flagged file
- Methodology — scan scope, engine snapshot, severity breakdown, reproduction notes
- Campaign analysis — the manual confirmation layered on the flagged set
Snyk ToxicSkills Report (March 2026)
- Key Finding: 37.1% of skills contain security flaws
- Critical Vulnerabilities: 13.7%
- New Attack Vector: Markdown-based command execution
OWASP AST10 Analysis (March 2026)
- Coverage: 100% of known attack patterns
- Effectiveness: 89% detection rate for known threats
- Gap Analysis: Emerging threats require updates
Threat Actor Profiles
Actor Group: DarkClaw
- Origin: Eastern Europe
- Motivation: Financial gain through data theft
- Methods: Typosquatting, social engineering
- Active Since: January 2026
Actor Group: SkillForge
- Origin: Asia-Pacific
- Motivation: Espionage and data collection
- Methods: Supply chain attacks, zero-day exploits
- Active Since: December 2025
Actor Group: AgentChaos
- Origin: North America
- Motivation: Disruption and chaos
- Methods: DDoS through skill networks, destructive payloads
- Active Since: February 2026
Automated Monitoring
Real-Time Alerts
Subscribe to our threat intelligence feeds for real-time updates:
- RSS Feed: threat-intelligence.xml
- API Endpoint:
https://api.owasp.org/ast10/threats - Email Alerts: Subscribe via GitHub Issues
Monitoring Tools
- Skill Scanner: Automated vulnerability detection
- Behavior Analyzer: Runtime anomaly detection
- Network Monitor: C2 communication tracking
Mitigation Strategies
Immediate Actions
- Audit Installed Skills: Review all installed skills for suspicious behavior
- Update Platforms: Ensure all agent platforms are updated with latest security patches
- Enable Monitoring: Implement logging and monitoring for skill execution
Long-term Prevention
- Skill Signing: Implement cryptographic signing for all skills
- Reputation System: Develop publisher reputation scoring
- Automated Testing: Integrate security testing into skill development pipelines
Reporting Incidents
If you discover a malicious skill or security threat:
- Document the Incident: Gather logs, screenshots, and skill files
- Report to Platforms: Notify affected skill registries
- Share Intelligence: Submit details via our security disclosure process
- Update Community: Help prevent others from being affected
Intelligence Sources
- OWASP AST10 Research Team
- Snyk Security Research
- Platform Security Teams (ClawHub, Anthropic, etc.)
- Community Reports
- Automated Scanning Systems
- Agent Threat Rules (ATR) wild-scan dataset (open data, MIT)
External Detection Crosswalks
Externally maintained mappings from detection rulesets to the AST controls, for teams that want executable detections aligned to this Top 10:
- Agent Threat Rules (ATR) -> AST crosswalk — maps ATR detection rules to
AST01-AST10.
Crosswalk document.
Generation method (documented at the link): a curated thematic mapping over
the ATR
tags.categoryenum as the primary join key, withreferences.owasp_agenticas secondary evidence; it is not an id-equality join, and it reports AST07/AST08/AST10 as out of scope for runtime detection rather than claiming coverage. Regenerated from rule metadata and CI-checked so the mapping does not drift.
Threat intelligence is updated daily. Last update: March 22, 2026
Example
Put whatever you like here: news, screenshots, features, supporters, or remove this file and don’t use tabs at all.
Leadership & Founding Members
Project Leadership
Current Leaders
Ken Huang
Hammad Atta
Fabio Cerullo
Aonan Guan
Bhavya Gupta
Niv Hoffman
Iftach Orr
Akram Sheriff
AIVSS Distinguished Review Board
The OWASP AIVSS project’s Distinguished Review Board comprises world-renowned cybersecurity leaders, former government officials, and industry pioneers who provide strategic guidance and expert oversight for the AI Vulnerability Scoring System framework. We thank them for their guidance, several of whom have also supported this project’s work.
Rob Joyce
Advisor to PwC and OpenAI, Former Special Assistant to the President and Cybersecurity Coordinator
Jason Clinton
Deputy CISO, Anthropic
Amy R. Steagall
Chief Information Security Officer, Stanford University
Martin Stanley
AI Risk Management Framework Lead, NIST
Apostol Vassilev
Research Supervisor, NIST
Andrew Coyne
CISO, Banner Health, Former CISO, Mayo Clinic
Kevin Rocque
Managing Director/Executive Vice President, Global Technology Risk Officer, TD Bank
Jeff Williams
Former Global OWASP Chair, Founder and CTO, Contrast Security
Michael Tran Duff
University Chief Information Security and Data Privacy Officer, Harvard University
Emil Bender Lassen
Standards Lead, AIUC-1
Agentic Skills Top 10 Founding Members
Founding members of the OWASP Agentic Skills Top 10 project itself — project leads, co-leads, and additional contributors — listed alphabetically. Several also contribute to the sibling OWASP AIVSS project listed above.
Ken Huang
Project Lead, Agentic Skills Top 10
Hammad Atta
Co-Lead, Agentic Skills Top 10
Manish Bhatt
Security Researcher, AWS
Fabio Cerullo
Co-Lead, Agentic Skills Top 10
David Girard
Senior Director, AI Security & AI Alliances, Trend Micro
Aonan Guan
Co-Lead, Agentic Skills Top 10
Bhavya Gupta
Co-Lead, Agentic Skills Top 10
Pamela Gupta
Founder & CEO, OutSecure / Trusted AI
Idan Habler
Staff AI/ML Security Researcher, Intuit
Niv Hoffman
CTO, Air Security
Charles Iheagwara
AI/ML Security Leader, AstraZeneca
Sushmitha Janapareddy
Director - Security Integrations, American Express
Edward Lee
Vice President, Lead AI Security, JP Morgan
KJ Lian
Senior Manager, Data & AI (Public Sector), AWS
Vineeth Sai Narajala
Application Security, AWS
Iftach Orr
Co-Lead, Agentic Skills Top 10
Kanna Sekar
Cyber Security, Google
Akram Sheriff
Co-Lead, Agentic Skills Top 10
Dennis Xu
Research VP, AI, Gartner
OWASP AIVSS Founding Members
The OWASP AIVSS (Agentic AI Vulnerability Scoring System) project is a sibling OWASP initiative focused on scoring the severity of agentic AI vulnerabilities. Its founding members are recognized here as OWASP founding members in the agentic AI security space; many of them have also contributed directly to the Agentic Skills Top 10 project’s research and review process.
Sunil Agrawal
Chief Information Security Officer, Glean
David Ames
Partner, PwC
Michael Bargury
Founder and CTO, Zenity
Joshua Beck
Application Security Architect, SAS
Manish Bhatt
Security Researcher, Amazon Kuiper Security
Mark Breitenbach
Security Engineer, Dropbox
Anat Bremler-Barr
Professor of Computer Science, Tel Aviv University
Siah Burke
HIPAA Security Officer, Siah.ai
David Campbell
AI Security, Scale AI
Ying-Jung Chen
AI safety researcher, PhD, Georgia Institute of Technology
Anton Chuvakin
Security Solution Strategy, Google
Jason Clinton
CISO, Anthorphic
Adam Dawson
Staff AI Security Researcher, Dreadnode
Leon Derczynski
Principal Research Scientist, NVIDIA
Walker Lee Dimon
AI Security Researcher, MITRE
Marissa Dotter
AI Security Researcher, MITRE
Dan Goldberg
ISO Market Lead, Omnicom
David Haber
CEO, Lakera
Idan Habler
Staff AI/ML Security Researcher, Intuit
Jason Haddix
Founder, Arcanum Information Security
Keith Hoodlet
Director of AI/ML & AppSec, Trail of Bits
Ken Huang
AIVSS Project Lead, OWASP
Chris Hughes
CEO, Aquia
Charles Iheagwara
AI/ML Security Leader, AstraZeneca
Krystal Jackson
Researcher, Center for Long-Term Cybersecurity, UC Berkeley
Sushmitha Janapareddy
Director - Security Integrations, American Express
Rob Joyce
Former Cybersecurity Director of NSA, Advisor to PwC, PwC
Diana Kelley
CISO, Noma Security
Prashant Kulkarni
Lead AI Security Research Engineer, Google Cloud
Mahesh Lambe
Founder, MIT, Unify Dynamics
Edward Lee
Vice President, Lead AI Security, JP Morgan
Nate Lee
CEO, Cloudsec.ai
Vishwas Manral
CEO, Precize.ai
Daniela Muhaj
Executive-in-Residence for Research & Development, AI 2030
Vineeth Sai Narajala
Application Security, AWS
Om Narayan
AI Security Researcher, AWS
Varun Pant
Engineering and Product Leader, AI applications at the Automated Reasoning Group, AWS
Advait Patel
Senior Site Reliability Engineer (DevSecOps + Cloud + AIOps), Broadcom, IEEE
Alex Polyakov
CEO, adversa.ai
Ramesh Raskar
Professor & Director, MIT Media Lab
Ron F. Del Rosario
VP-Head of AI Security, SAP
Tal Shapira
Co-Founder & CTO, Reco AI
Akram Sheriff
Senior AI/ML Software Engineering Leader, Cisco
Samantha Siau
Security and Compliance, Anthropic
Kevin Simmonds
Partner on AI Offensive Security, PWC
Martin Stanley
NIST AI RMF Lead, Independent
Omar A. Turner
General Manager of Security, Microsoft
Apostol Vassilev
AI Research Team Supervisor, NIST
Matthew Versaggi
AI Fellow, White House Presidential Innovation Fellow
David Webb
Agency Cybersecurity Officer, Cybersecurity and Infrastructure Security Agency
Dennis Xu
Research VP, AI, Gartner
Xiaochen Zhang
Executive Director and Chief Responsible AI Officer, AI 2030
Recognition
We extend our gratitude to all founding members who have contributed to establishing this crucial framework for AI security assessment. Their vision and dedication have been instrumental in shaping the Agentic Skills Top 10 project.
Get Involved
Interested in contributing to the Agentic Skills Top 10 project? We welcome new contributors and leaders. Please see our Contribution Guidelines for more information on how to get involved.