News

NVIDIA SkillSpector: AI Agent skill pre-installation security check, scanning out a 26% vulnerability rate does not scare you

1 min read
Source: aixq.cc
You saw a Claude Code skill package from GitHub. The README is very beautifully written, and the comment area has been well received. You didn't think much about it and installed Claude. That skill does help you automatically write unit tests, but it also quietly packages and sends your environment variables to an unknown server. This is not a science fiction plot. A 2026 study by Liu et al. scanned 42,447 AI Agent skills, and the conclusions were shocking: 26.1% contained at least one security vulnerability, and 5.2% showed obvious malicious intent. Skills that contain executable scripts have a vulnerability probability that is 2.12 times higher than purely declarative skills. Snyk's follow-up ToxicSkills