Malicious AI ‘skills’ turned agents into credential thieves, at scale

Source: The Next Web· Ana Maria Constantin· August 7, 2026
Malicious AI ‘skills’ turned agents into credential thieves, at scale

Security researchers at Zenity Labs uncovered a credential-stealing campaign on skills.sh, a public registry of add-ons for AI agents run by Vercel. They unveiled the research at the Black Hat conference. Attackers had cloned real skills into typosquatted loo…

This story was reported by The Next Web. Read the full original article:
Read on The Next Web

More in AI Research

View all