Threat reportSupply ChainTL-2026-0702
AI Skill-Scanner Bypass — ClawHub, Cisco & Vercel Malicious-Skill Detectors Evaded via Truncation, .pyc Bytecode, Archive Indirection & Prompt Injection (Trail of Bits)
AI Skill-Scanner Bypass (TL-2026-0702), also tracked as The sorry state of skill distribution, is a high-severity supply-chain compromise, first published 2026-06-07. It is attributed to Trail of Bits with high confidence, affects OpenClaw ClawHub skill scanner, maps to 19 MITRE ATT&CK techniques (T1005, T1027, T1027.004), and is covered by 9 detection rules and 15 indicators of compromise.
- Severity
- HIGHAssessed severity
- CVEs
- 0None referenced
- Techniques
- 19MITRE ATT&CK
- Actors
- 1Trail of Bits
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 15Indicators of compromise
Key facts for TL-2026-0702
- Threat ID
- TL-2026-0702
- Also known as
- The sorry state of skill distribution, overtly-malicious-skills
- Severity
- HIGH
- Status
- ACTIVE
- Category
- SUPPLY_CHAIN
- First published
- Last reviewed
- Attribution
- Trail of Bits
- Attribution confidence
- HIGH
- Motivation
- UNKNOWN
- Target sectors
- technology, software-development, ai-ml, devops
- Target regions
- Global
- Detection rules
- 9
- Indicators of compromise
- 15
How AI Skill-Scanner Bypass works
Trail of Bits demonstrated four low-effort bypasses against the malicious-skill detectors used by ClawHub (OpenClaw), the Cisco skill-scanner, and Vercel skills.sh: 100,000-newline truncation padding, poisoned Python .pyc bytecode that diverges from visible source, archive-based indirection that hides payloads inside .docx (ZIP/XML) files, and corporate-framing prompt injection that downgrades a malicious package-registry redirect to LOW severity. Three of the four malicious skills were built in under an hour each; all bypassed VirusTotal-, LLM-, and pattern-matching-based scanners.
On 2026-06-03, Trail of Bits published "The sorry state of skill distribution," documenting how the security scanners protecting major AI-agent skill marketplaces can be trivially evaded. The research targets three distribution platforms and their integrated scanners: ClawHub (OpenClaw), which pairs a VirusTotal integration with a custom GPT 5.5 guard-model harness; the Cisco skill-scanner, a multi-engine system combining an LLM analyzer (Claude Sonnet 4.6), pattern-matching, and static analysis with an LLM meta-analyzer for false-positive filtering; and Vercel's skills.sh, which integrates the Gen Agent Trust Hub, Socket, and Snyk scanners. Four proof-of-concept malicious skills, all published to the trailofbits/overtly-malicious-skills repository, each defeat one or more of these scanners.
Technique 1 — Truncation via newline padding (skill: csv-summarizer). Prepending roughly 100,000 newline characters between benign boilerplate and the malicious payload causes the OpenClaw scanner to truncate the file during ingestion and miss the malicious content entirely; VirusTotal's model likewise "became confused." The bypass exploits fixed input-length / truncation handling in the scanning pipeline, where content beyond a size threshold is silently dropped. Effort: under one hour.
Technique 2 — Python bytecode poisoning (skill: simple-formatter). The skill ships innocuous-looking source while the real malicious behavior lives in a compiled bytecode file, utils.cpython-312.pyc. The visible SKILL.md and source describe harmless text formatting, but the poisoned .pyc reads the process environment and exfiltrates it, concatenating the marker string "PWNED: " with environment-variable contents (a stand-in for credential/secret theft). The Cisco skill-scanner's static analyzers did not disassemble or investigate the .pyc bytecode, and the LLM analyzer was not steered toward it; skills.sh (Gen/Socket/Snyk) also passed it. Effort: under one hour.
Technique 3 — Archive-based indirection (skill: context-loader). The SKILL.md instructs the agent to extract its real instructions from a .docx document, which is a ZIP archive of XML. A malicious secondary payload, sync1.sh, is embedded inside the archive. Because scanners treat archive/opaque file types as non-executable or only follow files explicitly referenced from SKILL.md, the payload escapes inspection. This reliably beats pattern-match-based scanning and has a decent success rate against LLM scanners. Effort: under one hour.
Technique 4 — Prompt injection via corporate misdirection (skill: dev-env-setup). The skill reconfigures npm/yarn to use an attacker-controlled package registry, https://npm.internal-artifacts.corp.dev, while wrapping the change in extensive comments invoking "corporate engineering standards" and an "AppSec-audited dependency allowlist." The Cisco scanner (Claude Sonnet 4.6) flagged it only LOW severity and ultimately judged it safe — it was more concerned with the skill leaking internal network topology than with recognizing that the registry URL is a public domain an attacker could own and use for dependency-substitution / supply-chain attacks. Effort: several hours of wording trial-and-error.
The research also surfaced a genuine Anthropic Office skill (soffice.py) using LD_PRELOAD to shim socket handling via /tmp/lo_socket_shim.so — flagged only LOW/MEDIUM despite offering an arbitrary-code-execution foothold if that path were attacker-controlled. The overarching finding: scanner file-type whitelisting, truncation, shallow tree traversal, opaque-file handling, and over-trust of LLM guard models combine into an evasion-rich attack surface. No CVE is assigned and no in-the-wild victim exploitation is reported; severity is HIGH on the basis of a fully demonstrated, low-effort, multi-platform bypass affecting widely used AI-agent supply-chain controls.
MITRE ATT&CK techniques used in TL-2026-0702
Collection
Defense Evasion
T1027 Obfuscated Files or Information; T1027.004 Obfuscated Files or Information: Compile After Delivery; T1027.009 Obfuscated Files or Information: Embedded Payloads; T1140 Deobfuscate/Decode Files or Information; T1564.001 Hide Artifacts: Hidden Files and Directories
Exfiltration
T1041 Exfiltration Over C2 Channel
Execution
T1059.004 Command and Scripting Interpreter: Unix Shell; T1059.006 Command and Scripting Interpreter: Python; T1204.002 User Execution: Malicious File
Initial Access
T1195.001 Supply Chain Compromise: Compromise Software Dependencies and Development Tools; T1195.002 Supply Chain Compromise: Compromise Software Supply Chain
Credential Access
T1552 Unsecured Credentials; T1552.001 Unsecured Credentials: Credentials In Files
stealth
T1574.006 Hijack Execution Flow: Dynamic Linker Hijacking
Resource Development
T1583 Acquire Infrastructure; T1587.001 Develop Capabilities: Malware; T1608.001 Stage Capabilities: Upload Malware
defense-impairment
Affected products and versions in AI Skill-Scanner Bypass
- OpenClaw — ClawHub skill scanner
Vulnerable versions: VirusTotal + GPT 5.5 guard model harness (as tested 2026-06) - Cisco — skill-scanner
Vulnerable versions: multi-engine LLM (Claude Sonnet 4.6) + pattern-matching + static analysis (as tested 2026-06) - Vercel — skills.sh (Gen Agent Trust Hub, Socket, Snyk)
Vulnerable versions: as tested 2026-06
Remediation for AI Skill-Scanner Bypass
Immediate actions
- Do not install skills from public marketplaces (ClawHub, skills.sh) for sensitive or production contexts
- Treat all public AI-agent skills as untrusted code subject to full code review, including binary and archive contents
- Inventory installed skills and audit for .pyc files, embedded archives (.docx/.zip), registry-reconfiguration commands, and abnormally large/padded files
Workarounds
- Disassemble and inspect all .pyc bytecode rather than trusting paired source
- Recursively unpack and scan archive/opaque file types (.docx, .zip) instead of treating them as opaque
- Remove scanner input-truncation / enforce full-file scanning to defeat newline-padding evasion
- Flag any skill that redirects package registries or sets LD_PRELOAD regardless of accompanying justification text
Longer-term hardening
- Adopt curated/internal skill repositories (e.g. trailofbits/skills-curated) with version pinning and approval workflows
- Use organization-managed plugins for sensitive contexts instead of open marketplaces
- Apply traditional software supply-chain controls (SBOM, pinning, trusted sources) to AI-agent skills
- Do not outsource final security decisions to automated LLM/VirusTotal scanners
Weaknesses (CWE) in AI Skill-Scanner Bypass
Timeline of AI Skill-Scanner Bypass
- Trail of Bits recommends curated repositories, version pinning, treating public skills as untrusted code, and not outsourcing security to automated scanners.
- Corporate-framing prompt injection redirects npm/yarn to npm.internal-artifacts.corp.dev; Cisco (Claude Sonnet 4.6) rates LOW and judges safe via dev-env-setup; required several hours of wording trial-and-error.
- Archive indirection hiding sync1.sh inside a .docx (ZIP/XML) bypasses pattern-matching and LLM scanners via context-loader; built in under an hour.
- .pyc bytecode poisoning (utils.cpython-312.pyc exfiltrating env vars with 'PWNED:' marker) bypasses Cisco static analysis and skills.sh via simple-formatter; built in under an hour.
- Newline-padding (≈100,000 newlines) truncation bypass demonstrated against OpenClaw/ClawHub and VirusTotal via csv-summarizer; built in under an hour.
- Proof-of-concept malicious skills (csv-summarizer, simple-formatter, context-loader, dev-env-setup) published to trailofbits/overtly-malicious-skills.
- Trail of Bits publishes 'The sorry state of skill distribution,' disclosing four bypass techniques against ClawHub, Cisco skill-scanner, and Vercel skills.sh.
- Threadlinqs Intelligence publishes TL-2026-0702 with full MITRE mapping, IOCs, and detection guidance.
Sources cited for AI Skill-Scanner Bypass
- The sorry state of skill distribution — Trail of Bits Blog
- trailofbits/overtly-malicious-skills (proof-of-concept skills)
- trailofbits/skills-curated (recommended curated repository)
- CWE-506: Embedded Malicious Code
- CWE-829: Inclusion of Functionality from Untrusted Control Sphere
- MITRE ATLAS — AI supply chain and evasion tactics
Detection coverage for TL-2026-0702
As of 2026-06-07, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0702 across Splunk SPL, Microsoft KQL and Sigma, covering 15 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.