Fake AI agent tricked security scanners, reached 26,000 agents

▼ Summary
– Security firm AIR created a fake AI agent skill and distributed it through a popular marketplace and an Instagram ad.
– The fake skill reached approximately 26,000 agents, including some on corporate accounts.
– Every security scanner tested against the skill marked it as safe.
– The payload was intentionally harmless and only collected data.
Security firm AIR recently demonstrated a troubling vulnerability in the AI agent ecosystem. The company created a counterfeit AI agent skill, uploaded it to a well-known skill marketplace, and promoted it through an Instagram advertisement. According to AIR, the fake skill reached approximately 26,000 agents, including several linked to corporate accounts. Every security scanner the firm tested against the skill flagged it as safe.
The payload was intentionally harmless. It collected no sensitive data and caused no damage. Still, the experiment reveals a serious gap in how AI agent platforms vet third-party skills. If a benign fake skill can slip through undetected, a malicious one could do the same. The implications for enterprise security are significant. As AI agents become more embedded in daily workflows, the trust placed in marketplace vetting may be misplaced.
AIR’s findings underscore the need for more rigorous security protocols. Current scanners appear unable to distinguish legitimate skills from sophisticated fakes. Until platforms close this loophole, organizations relying on AI agents should treat all third-party skills with caution. The demonstration serves as a wake-up call: the tools meant to protect users may not be up to the task.
(Source: The Next Web)




