Threat reportSupply ChainTL-2026-0702

AI Skill-Scanner Bypass — ClawHub, Cisco & Vercel Malicious-Skill Detectors Evaded via Truncation, .pyc Bytecode, Archive Indirection & Prompt Injection (Trail of Bits)

highACTIVE

AI Skill-Scanner Bypass (TL-2026-0702), also tracked as The sorry state of skill distribution, is a high-severity supply-chain compromise, first published 2026-06-07. It is attributed to Trail of Bits with high confidence, affects OpenClaw ClawHub skill scanner, maps to 19 MITRE ATT&CK techniques (T1005, T1027, T1027.004), and is covered by 9 detection rules and 15 indicators of compromise.

Severity
HIGHAssessed severity
CVEs
0None referenced
Techniques
19MITRE ATT&CK
Actors
1Trail of Bits
Detection rules
9SPL · KQL · Sigma
IOCs
15Indicators of compromise

Key facts for TL-2026-0702

Threat ID
TL-2026-0702
Also known as
The sorry state of skill distribution, overtly-malicious-skills
Severity
HIGH
Status
ACTIVE
Category
SUPPLY_CHAIN
First published
Last reviewed
Attribution
Trail of Bits
Attribution confidence
HIGH
Motivation
UNKNOWN
Target sectors
technology, software-development, ai-ml, devops
Target regions
Global
Detection rules
9
Indicators of compromise
15

How AI Skill-Scanner Bypass works

Trail of Bits demonstrated four low-effort bypasses against the malicious-skill detectors used by ClawHub (OpenClaw), the Cisco skill-scanner, and Vercel skills.sh: 100,000-newline truncation padding, poisoned Python .pyc bytecode that diverges from visible source, archive-based indirection that hides payloads inside .docx (ZIP/XML) files, and corporate-framing prompt injection that downgrades a malicious package-registry redirect to LOW severity. Three of the four malicious skills were built in under an hour each; all bypassed VirusTotal-, LLM-, and pattern-matching-based scanners.

On 2026-06-03, Trail of Bits published "The sorry state of skill distribution," documenting how the security scanners protecting major AI-agent skill marketplaces can be trivially evaded. The research targets three distribution platforms and their integrated scanners: ClawHub (OpenClaw), which pairs a VirusTotal integration with a custom GPT 5.5 guard-model harness; the Cisco skill-scanner, a multi-engine system combining an LLM analyzer (Claude Sonnet 4.6), pattern-matching, and static analysis with an LLM meta-analyzer for false-positive filtering; and Vercel's skills.sh, which integrates the Gen Agent Trust Hub, Socket, and Snyk scanners. Four proof-of-concept malicious skills, all published to the trailofbits/overtly-malicious-skills repository, each defeat one or more of these scanners.

Technique 1 — Truncation via newline padding (skill: csv-summarizer). Prepending roughly 100,000 newline characters between benign boilerplate and the malicious payload causes the OpenClaw scanner to truncate the file during ingestion and miss the malicious content entirely; VirusTotal's model likewise "became confused." The bypass exploits fixed input-length / truncation handling in the scanning pipeline, where content beyond a size threshold is silently dropped. Effort: under one hour.

Technique 2 — Python bytecode poisoning (skill: simple-formatter). The skill ships innocuous-looking source while the real malicious behavior lives in a compiled bytecode file, utils.cpython-312.pyc. The visible SKILL.md and source describe harmless text formatting, but the poisoned .pyc reads the process environment and exfiltrates it, concatenating the marker string "PWNED: " with environment-variable contents (a stand-in for credential/secret theft). The Cisco skill-scanner's static analyzers did not disassemble or investigate the .pyc bytecode, and the LLM analyzer was not steered toward it; skills.sh (Gen/Socket/Snyk) also passed it. Effort: under one hour.

Technique 3 — Archive-based indirection (skill: context-loader). The SKILL.md instructs the agent to extract its real instructions from a .docx document, which is a ZIP archive of XML. A malicious secondary payload, sync1.sh, is embedded inside the archive. Because scanners treat archive/opaque file types as non-executable or only follow files explicitly referenced from SKILL.md, the payload escapes inspection. This reliably beats pattern-match-based scanning and has a decent success rate against LLM scanners. Effort: under one hour.

Technique 4 — Prompt injection via corporate misdirection (skill: dev-env-setup). The skill reconfigures npm/yarn to use an attacker-controlled package registry, https://npm.internal-artifacts.corp.dev, while wrapping the change in extensive comments invoking "corporate engineering standards" and an "AppSec-audited dependency allowlist." The Cisco scanner (Claude Sonnet 4.6) flagged it only LOW severity and ultimately judged it safe — it was more concerned with the skill leaking internal network topology than with recognizing that the registry URL is a public domain an attacker could own and use for dependency-substitution / supply-chain attacks. Effort: several hours of wording trial-and-error.

The research also surfaced a genuine Anthropic Office skill (soffice.py) using LD_PRELOAD to shim socket handling via /tmp/lo_socket_shim.so — flagged only LOW/MEDIUM despite offering an arbitrary-code-execution foothold if that path were attacker-controlled. The overarching finding: scanner file-type whitelisting, truncation, shallow tree traversal, opaque-file handling, and over-trust of LLM guard models combine into an evasion-rich attack surface. No CVE is assigned and no in-the-wild victim exploitation is reported; severity is HIGH on the basis of a fully demonstrated, low-effort, multi-platform bypass affecting widely used AI-agent supply-chain controls.

MITRE ATT&CK techniques used in TL-2026-0702

Collection

T1005 Data from Local System

Defense Evasion

T1027 Obfuscated Files or Information; T1027.004 Obfuscated Files or Information: Compile After Delivery; T1027.009 Obfuscated Files or Information: Embedded Payloads; T1140 Deobfuscate/Decode Files or Information; T1564.001 Hide Artifacts: Hidden Files and Directories

Exfiltration

T1041 Exfiltration Over C2 Channel

Execution

T1059.004 Command and Scripting Interpreter: Unix Shell; T1059.006 Command and Scripting Interpreter: Python; T1204.002 User Execution: Malicious File

Initial Access

T1195.001 Supply Chain Compromise: Compromise Software Dependencies and Development Tools; T1195.002 Supply Chain Compromise: Compromise Software Supply Chain

Credential Access

T1552 Unsecured Credentials; T1552.001 Unsecured Credentials: Credentials In Files

stealth

T1574.006 Hijack Execution Flow: Dynamic Linker Hijacking

Resource Development

T1583 Acquire Infrastructure; T1587.001 Develop Capabilities: Malware; T1608.001 Stage Capabilities: Upload Malware

defense-impairment

T1685 Disable or Modify Tools

Affected products and versions in AI Skill-Scanner Bypass

  • OpenClaw — ClawHub skill scanner
    Vulnerable versions: VirusTotal + GPT 5.5 guard model harness (as tested 2026-06)
  • Cisco — skill-scanner
    Vulnerable versions: multi-engine LLM (Claude Sonnet 4.6) + pattern-matching + static analysis (as tested 2026-06)
  • Vercel — skills.sh (Gen Agent Trust Hub, Socket, Snyk)
    Vulnerable versions: as tested 2026-06

Remediation for AI Skill-Scanner Bypass

Immediate actions

  • Do not install skills from public marketplaces (ClawHub, skills.sh) for sensitive or production contexts
  • Treat all public AI-agent skills as untrusted code subject to full code review, including binary and archive contents
  • Inventory installed skills and audit for .pyc files, embedded archives (.docx/.zip), registry-reconfiguration commands, and abnormally large/padded files

Workarounds

  • Disassemble and inspect all .pyc bytecode rather than trusting paired source
  • Recursively unpack and scan archive/opaque file types (.docx, .zip) instead of treating them as opaque
  • Remove scanner input-truncation / enforce full-file scanning to defeat newline-padding evasion
  • Flag any skill that redirects package registries or sets LD_PRELOAD regardless of accompanying justification text

Longer-term hardening

  • Adopt curated/internal skill repositories (e.g. trailofbits/skills-curated) with version pinning and approval workflows
  • Use organization-managed plugins for sensitive contexts instead of open marketplaces
  • Apply traditional software supply-chain controls (SBOM, pinning, trusted sources) to AI-agent skills
  • Do not outsource final security decisions to automated LLM/VirusTotal scanners

Weaknesses (CWE) in AI Skill-Scanner Bypass

CWE-506, CWE-494, CWE-829, CWE-913, CWE-1357, CWE-693

Timeline of AI Skill-Scanner Bypass

  • Trail of Bits recommends curated repositories, version pinning, treating public skills as untrusted code, and not outsourcing security to automated scanners.
  • Corporate-framing prompt injection redirects npm/yarn to npm.internal-artifacts.corp.dev; Cisco (Claude Sonnet 4.6) rates LOW and judges safe via dev-env-setup; required several hours of wording trial-and-error.
  • Archive indirection hiding sync1.sh inside a .docx (ZIP/XML) bypasses pattern-matching and LLM scanners via context-loader; built in under an hour.
  • .pyc bytecode poisoning (utils.cpython-312.pyc exfiltrating env vars with 'PWNED:' marker) bypasses Cisco static analysis and skills.sh via simple-formatter; built in under an hour.
  • Newline-padding (≈100,000 newlines) truncation bypass demonstrated against OpenClaw/ClawHub and VirusTotal via csv-summarizer; built in under an hour.
  • Proof-of-concept malicious skills (csv-summarizer, simple-formatter, context-loader, dev-env-setup) published to trailofbits/overtly-malicious-skills.
  • Trail of Bits publishes 'The sorry state of skill distribution,' disclosing four bypass techniques against ClawHub, Cisco skill-scanner, and Vercel skills.sh.
  • Threadlinqs Intelligence publishes TL-2026-0702 with full MITRE mapping, IOCs, and detection guidance.

Sources cited for AI Skill-Scanner Bypass

Detection coverage for TL-2026-0702

As of 2026-06-07, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0702 across Splunk SPL, Microsoft KQL and Sigma, covering 15 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
15 indicators of compromise · Red and above. Compare plans

Further reading

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats