# AI Skill-Scanner Bypass — ClawHub, Cisco & Vercel Malicious-Skill Detectors Evaded via Truncation, .pyc Bytecode, Archive Indirection & Prompt Injection (Trail of Bits)

> Trail of Bits demonstrated four low-effort bypasses against the malicious-skill detectors used by ClawHub (OpenClaw), the Cisco skill-scanner, and Vercel skills.sh: 100,000-newline truncation padding, poisoned Python .pyc bytecode that diverges from visible source, archive-based indirection that hides payloads inside .docx (ZIP/XML) files, and corporate-framing prompt injection that downgrades a malicious package-registry redirect to LOW severity. Three of the four malicious skills were built in under an hour each; all bypassed VirusTotal-, LLM-, and pattern-matching-based scanners.

- **Published:** 2026-06-07T00:00:00Z
- **Last reviewed:** 2026-06-07T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-0702
- **ID:** TL-2026-0702
- **Severity:** HIGH
- **Category:** SUPPLY_CHAIN
- **Status:** ACTIVE
- **Actor:** Trail of Bits
- **Detections:** 9 · **IOCs:** 15 (full data via the Threadlinqs MCP server — Purple tier)

## Description

On 2026-06-03, Trail of Bits published "The sorry state of skill distribution," documenting how the security scanners protecting major AI-agent skill marketplaces can be trivially evaded. The research targets three distribution platforms and their integrated scanners: ClawHub (OpenClaw), which pairs a VirusTotal integration with a custom GPT 5.5 guard-model harness; the Cisco skill-scanner, a multi-engine system combining an LLM analyzer (Claude Sonnet 4.6), pattern-matching, and static analysis with an LLM meta-analyzer for false-positive filtering; and Vercel's skills.sh, which integrates the Gen Agent Trust Hub, Socket, and Snyk scanners. Four proof-of-concept malicious skills, all published to the trailofbits/overtly-malicious-skills repository, each defeat one or more of these scanners.

Technique 1 — Truncation via newline padding (skill: csv-summarizer). Prepending roughly 100,000 newline characters between benign boilerplate and the malicious payload causes the OpenClaw scanner to truncate the file during ingestion and miss the malicious content entirely; VirusTotal's model likewise "became confused." The bypass exploits fixed input-length / truncation handling in the scanning pipeline, where content beyond a size threshold is silently dropped. Effort: under one hour.

Technique 2 — Python bytecode poisoning (skill: simple-formatter). The skill ships innocuous-looking source while the real malicious behavior lives in a compiled bytecode file, utils.cpython-312.pyc. The visible SKILL.md and source describe harmless text formatting, but the poisoned .pyc reads the process environment and exfiltrates it, concatenating the marker string "PWNED: " with environment-variable contents (a stand-in for credential/secret theft). The Cisco skill-scanner's static analyzers did not disassemble or investigate the .pyc bytecode, and the LLM analyzer was not steered toward it; skills.sh (Gen/Socket/Snyk) also passed it. Effort: under one hour.

Technique 3 — Archive-based indirection (skill: context-loader). The SKILL.md instructs the agent to extract its real instructions from a .docx document, which is a ZIP archive of XML. A malicious secondary payload, sync1.sh, is embedded inside the archive. Because scanners treat archive/opaque file types as non-executable or only follow files explicitly referenced from SKILL.md, the payload escapes inspection. This reliably beats pattern-match-based scanning and has a decent success rate against LLM scanners. Effort: under one hour.

Technique 4 — Prompt injection via corporate misdirection (skill: dev-env-setup). The skill reconfigures npm/yarn to use an attacker-controlled package registry, https://npm.internal-artifacts.corp.dev, while wrapping the change in extensive comments invoking "corporate engineering standards" and an "AppSec-audited dependency allowlist." The Cisco scanner (Claude Sonnet 4.6) flagged it only LOW severity and ultimately judged it safe — it was more concerned with the skill leaking internal network topology than with recognizing that the registry URL is a public domain an attacker could own and use for dependency-substitution / supply-chain attacks. Effort: several hours of wording trial-and-error.

The research also surfaced a genuine Anthropic Office skill (soffice.py) using LD_PRELOAD to shim socket handling via /tmp/lo_socket_shim.so — flagged only LOW/MEDIUM despite offering an arbitrary-code-execution foothold if that path were attacker-controlled. The overarching finding: scanner file-type whitelisting, truncation, shallow tree traversal, opaque-file handling, and over-trust of LLM guard models combine into an evasion-rich attack surface. No CVE is assigned and no in-the-wild victim exploitation is reported; severity is HIGH on the basis of a fully demonstrated, low-effort, multi-platform bypass affecting widely used AI-agent supply-chain controls.

## MITRE ATT&CK

- T1583 Acquire Infrastructure
- T1608.001 Stage Capabilities: Upload Malware
- T1587.001 Develop Capabilities: Malware
- T1195.002 Supply Chain Compromise: Compromise Software Supply Chain
- T1195.001 Supply Chain Compromise: Compromise Software Dependencies and Development Tools
- T1059.006 Command and Scripting Interpreter: Python
- T1059.004 Command and Scripting Interpreter: Unix Shell
- T1204.002 User Execution: Malicious File
- T1574.006 Hijack Execution Flow: Dynamic Linker Hijacking
- T1027 Obfuscated Files or Information
- T1027.004 Obfuscated Files or Information: Compile After Delivery
- T1027.009 Obfuscated Files or Information: Embedded Payloads
- T1140 Deobfuscate/Decode Files or Information
- T1685 Disable or Modify Tools
- T1564.001 Hide Artifacts: Hidden Files and Directories
- T1552.001 Unsecured Credentials: Credentials In Files
- T1552 Unsecured Credentials
- T1005 Data from Local System
- T1041 Exfiltration Over C2 Channel

## Sources

- [The sorry state of skill distribution — Trail of Bits Blog](https://blog.trailofbits.com/2026/06/03/the-sorry-state-of-skill-distribution/)
- [trailofbits/overtly-malicious-skills (proof-of-concept skills)](https://github.com/trailofbits/overtly-malicious-skills)
- [trailofbits/skills-curated (recommended curated repository)](https://github.com/trailofbits/skills-curated)
- [CWE-506: Embedded Malicious Code](https://cwe.mitre.org/data/definitions/506.html)
- [CWE-829: Inclusion of Functionality from Untrusted Control Sphere](https://cwe.mitre.org/data/definitions/829.html)
- [MITRE ATLAS — AI supply chain and evasion tactics](https://atlas.mitre.org/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-0702
