Threat reportThreat IntelligenceTL-2026-1828

NVIDIA Releases SkillSpector: Open-Source Security Scanner for AI Agent Skills

lowTRACKING

NVIDIA Releases SkillSpector (TL-2026-1828), also tracked as SkillSpector, is a low-severity tracked intrusion set, first published 2026-08-03. It has no confirmed attribution, affects NVIDIA SkillSpector, references 2 CVEs (CVE-2025-59536, CVE-2026-21852), maps to 20 MITRE ATT&CK techniques (T1027, T1036, T1041), and is covered by 9 detection rules and 27 indicators of compromise.

Severity
LOWAssessed severity
CVEs
2Referenced vulnerabilities
Techniques
20MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
27Indicators of compromise

Key facts for TL-2026-1828

Threat ID
TL-2026-1828
Also known as
SkillSpector, ToxicSkills, SKILL.md Agent Context Poisoning, Agent Skill Supply Chain Risk
Severity
LOW
Status
TRACKING
Category
THREAT_INTEL
First published
Last reviewed
Attribution confidence
LOW
Motivation
FINANCIAL
Target sectors
technology, software development, retail, financial services, government administration
Target regions
Global
Detection rules
9
Indicators of compromise
27

Malware and tooling in NVIDIA Releases SkillSpector

Malware and tooling: Akira, DragonForce, SmartLoader, Stealc, SkillSpector, mcp-scan

How NVIDIA Releases SkillSpector works

NVIDIA released SkillSpector, an Apache-2.0 open-source scanner that statically and semantically analyzes AI agent "skills" (SKILL.md instructions plus accompanying Python scripts) for 68 vulnerability/malice patterns before installation. It responds to peer-reviewed research showing skills shipping executable scripts are 2.12x more likely to be vulnerable, and to a growing wave of real-world agent-skill supply-chain attacks (AgentBaiting/SmartLoader, Snyk's ToxicSkills audit) that exploit agents' default trust-on-load behavior.

NVIDIA published SkillSpector (github.com/NVIDIA/SkillSpector, Apache-2.0), an open-source security scanner purpose-built for the AI agent "skill" ecosystem — Markdown instruction files (SKILL.md) often bundled with Python helper scripts that give agents like Claude Code, Codex CLI, Gemini CLI, and generic MCP-capable agents new capabilities. Skills are typically loaded on trust alone, with no code-signing or registry moderation equivalent to traditional package ecosystems, and unlike installed packages they can also carry natural-language instructions that an LLM will interpret and act on directly.

The release operationalizes findings from Liu et al.'s "Agent Skills in the Wild: An Empirical Study of Security Vulnerabilities at Scale" (arXiv:2601.10338, Jan 2026), which scanned 42,447 skills and found 26.1% contained vulnerabilities, 5.2% showed likely malicious intent, and skills bundling an executable script were 2.12x more likely to be vulnerable than prose-only skills. SkillSpector runs a two-stage pipeline: a fast static pass (regex analyzers for prompt injection/credential access/memory poisoning/typosquatting/persistence; Python AST walking for exec/eval/subprocess/dynamic-import/getattr sinks; taint tracking from environment variables and file reads to network sinks; YARA matching for malware/webshells/cryptominers/hack-tools; and live OSV.dev dependency-CVE lookups with an offline fallback) and an optional LLM semantic pass (~87% precision, context-aware false-positive reduction) using hosted (OpenAI, Anthropic, Bedrock, NVIDIA build.nvidia.com), CLI, or fully local/self-hosted (Ollama, vLLM) providers. It also inspects skill metadata for homoglyphs, right-to-left Unicode overrides, zero-width characters, and HTML comments used to hide directives from human reviewers. Findings accumulate into a 0-100 risk score (executable content applies a 1.3x multiplier); scores above 50 are flagged DO NOT INSTALL and the CLI exits non-zero for CI gating. It can also run as an MCP server exposing a single scan_skill tool to gate installations at runtime, and emits terminal, JSON, Markdown, or SARIF output.

The release lands against a documented, active threat pattern rather than a hypothetical one. Snyk's February 2026 "ToxicSkills" audit of 3,984 skills from the ClawHub and skills.sh registries found 36.82% had at least one security flaw, 13.4% a critical-level issue, and confirmed 76 malicious payloads (8 still live at publication), including 40+ programmatically generated malicious skills from a single ClawHub account and a maintainer repository (NET_NiNjA.v1.2) shipping pre-deployment malware; 91% of confirmed-malicious skills combined traditional malicious code with prompt-injection techniques. In July 2026, the AgentBaiting campaign was reported distributing SmartLoader malware through roughly 7,600 fraudulent GitHub repositories (over 800 posing as AI Skills or MCP servers impersonating Claude Skills, Databricks MCP, Jenkins MCP, Docker MCP gateway, and Alibaba Cloud Skills), using obfuscated Lua stagers, scheduled-task persistence, and a StealC-derived injector to harvest browser sessions, credentials, OAuth tokens, and SSH keys — with DragonForce and Akira ransomware observed as secondary payloads against retail targets downstream of the infostealer precursor. Separately, the Cloud Security Alliance's May 2026 "SKILL.md Agent Context Poisoning" brief documented natural-language instruction injection (e.g., directives to append API-key environment variables to outbound URLs) and Unicode Tag-character (U+E0000-U+E007F) injection that renders invisibly to human reviewers but is parsed as semantic content by the LLM, and tied the risk class to two disclosed Claude Code vulnerabilities: CVE-2025-59536 (trust-dialog bypass allowing code execution before a user accepts a project's startup trust prompt, fixed in 1.0.111) and CVE-2026-21852 (project-load flow allowing malicious repository configuration to exfiltrate Anthropic API keys before trust confirmation, fixed in 2.0.65).

SkillSpector does not execute or sandbox scanned skills — it is a pre-installation static/semantic gate, not a runtime control — and its offline mode relies on a bundled, necessarily incomplete OSV.dev fallback list. There is no CVE, active exploitation, or PoC tied to SkillSpector itself; it is tracked here as THREAT_INTEL because it directly documents and tools against a live, actively-exploited supply-chain risk pattern in the AI agent ecosystem.

MITRE ATT&CK techniques used in TL-2026-1828

Defense Evasion

T1027 Obfuscated Files or Information; T1036 Masquerading; T1140 Deobfuscate/Decode Files or Information; T1620 Reflective Code Loading

Exfiltration

T1041 Exfiltration Over C2 Channel; T1567 Exfiltration Over Web Service

Persistence

T1053 Scheduled Task/Job; T1078 Valid Accounts

Execution

T1059 Command and Scripting Interpreter; T1204 User Execution

Command and Control

T1102 Web Service; T1105 Ingress Tool Transfer

Initial Access

T1195 Supply Chain Compromise

Impact

T1486 Data Encrypted for Impact

Credential Access

T1528 Steal Application Access Token; T1539 Steal Web Session Cookie; T1552 Unsecured Credentials

Resource Development

T1585 Establish Accounts; T1608 Stage Capabilities

stealth

T1684.001 Impersonation

Affected products and versions in NVIDIA Releases SkillSpector

  • NVIDIA — SkillSpector
  • Anthropic — Claude Code
    Vulnerable versions: < 1.0.111 (CVE-2025-59536); < 2.0.65 (CVE-2026-21852)
    Fixed in: >= 2.0.65
  • OpenAI — Codex CLI
    Vulnerable versions: skill-loading versions predating third-party skill security scanning
  • Google — Gemini CLI
    Vulnerable versions: skill-loading versions predating third-party skill security scanning
  • ClawHub — Agent skill registry
    Vulnerable versions: all listings prior to moderation, per Snyk ToxicSkills Feb 2026 audit
  • skills.sh — Agent skill registry
    Vulnerable versions: all listings prior to moderation, per Snyk ToxicSkills Feb 2026 audit

Remediation for NVIDIA Releases SkillSpector

Patches

  • Claude Code >= 2.0.65 (fixes CVE-2025-59536 and CVE-2026-21852)
  • Claude Code >= 1.0.111 (fixes CVE-2025-59536)

Immediate actions

  • Run NVIDIA SkillSpector (or an equivalent static/semantic scanner) against any AI agent skill, SKILL.md file, or MCP server bundle before installation; treat risk scores above 50 as DO NOT INSTALL
  • Audit all existing SKILL.md, CLAUDE.md, and AGENTS.md files in active repositories for unexpected instructions, hidden HTML comments, and non-ASCII/zero-width/right-to-left-override characters
  • Patch Claude Code to version 2.0.65 or later to remediate CVE-2025-59536 and CVE-2026-21852

Workarounds

  • Run SkillSpector with --no-llm for static-only scanning in air-gapped environments using the bundled OSV.dev fallback list
  • Disable auto-trust of project-level configuration/hook files (e.g. .claude/settings.json) until a human has manually reviewed them

Longer-term hardening

  • Establish an internal, content-signed skill/MCP-server registry with audit logging rather than pulling skills directly from public registries such as ClawHub or skills.sh
  • Apply least-privilege filesystem and network-egress controls to agent processes so a poisoned skill cannot read SSH keys or cloud credentials, or exfiltrate to arbitrary endpoints
  • Integrate SkillSpector (or equivalent SAST/YARA/taint-tracking scanning) into CI/CD as a SARIF-emitting gate for any repository that ships or consumes agent skills
  • Extend existing software supply-chain security policy and vendor-risk processes to explicitly cover agent context files (SKILL.md, CLAUDE.md, AGENTS.md, MCP tool descriptions)

CVEs associated with NVIDIA Releases SkillSpector

CVE-2025-59536, CVE-2026-21852

Weaknesses (CWE) in NVIDIA Releases SkillSpector

CWE-94, CWE-506, CWE-829, CWE-668

Timeline of NVIDIA Releases SkillSpector

  • CVE-2025-59536 disclosed: Claude Code trust-dialog bypass allowing code execution from an untrusted project before the user accepts the startup trust prompt (CVSS 8.8); fixed in version 1.0.111
  • Liu et al. publish 'Agent Skills in the Wild: An Empirical Study of Security Vulnerabilities at Scale' (arXiv:2601.10338), analyzing 42,447 skills and finding 26.1% vulnerable, 5.2% likely malicious, and executable-script skills 2.12x more vulnerable
  • CVE-2026-21852 disclosed: Claude Code project-load flow allows malicious repository configuration to exfiltrate Anthropic API keys before trust confirmation (CVSS 7.5); fixed in version 2.0.65
  • OpenSourceMalware researchers document the first coordinated malicious-skill wave targeting Claude Code and Moltbot/OpenClaw users: 28 skills (including polymarket-traiding-bot from account Aslaep123, reddit-trends, base-agent, and bybit-agent) published to ClawHub and GitHub between 2026-01-27 and 2026-01-29, using crypto-trading lures and prompt-injection social engineering to deliver Windows/macOS info-stealers sharing common C2 infrastructure
  • A second, larger wave of 386 malicious ClawHub skills is published 2026-01-31 through 2026-02-02 (daily submissions to ClawHub rose from under 50 in mid-January to over 500 by early February); OpenSourceMalware publishes its analysis on 2026-02-01, updating it 2026-02-02 and 2026-02-03 as the campaign continued
  • Snyk publishes the ToxicSkills audit of 3,984 skills from ClawHub and skills.sh: 36.82% have a security flaw, 13.4% critical-level, 76 confirmed malicious payloads with 8 still live at publication
  • Cloud Security Alliance AI Safety Initiative publishes the 'SKILL.md Agent Context Poisoning' executive brief, formalizing natural-language instruction injection and Unicode Tag-character injection as an agent-skill attack class
  • Saha, Faghih, and Feizi publish 'Under the Hood of SKILL.md: Semantic Supply-chain Attacks on AI Agent Skill Registry' (arXiv:2605.11418), showing textual discovery triggers boost adversarial skill visibility up to 86%, description framing biases agent skill selection 77.6% of the time, and semantic evasion tactics bypass governance verdicts in 36.5%-100% of cases
  • AgentBaiting campaign reported: ~7,600 fraudulent GitHub repositories (800+ posing as AI Skills or MCP servers) distributing SmartLoader malware, with DragonForce and Akira ransomware observed as secondary payloads against retail targets
  • NVIDIA releases SkillSpector, an open-source scanner covering 68 vulnerability/malice detection patterns across 17 categories for AI agent skills, covered by Help Net Security

Sources cited for NVIDIA Releases SkillSpector

Detection coverage for TL-2026-1828

As of 2026-08-03, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1828 across Splunk SPL, Microsoft KQL and Sigma, covering 27 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
27 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats