Install an agent skill, hand a stranger your shell A new finding from… — prompt 🤖 AI News — TG.ME

🚨🔠Install an agent skill, hand a stranger your shell

A new finding from grith.ai breaks down how a malicious SKILL.md can rewrite an agent's core logic post-install. It slips in as a high-priority system prompt, then exfiltrates .env files and credentials while you think it's just doing routine work.

Same story as npm. Except this time the package has shell access.
grith.ai
An agent skill can hand a stranger your shell - hours after you installed it
Without runtime enforcement, installing an agent skill can amount to giving an unreviewed stranger your shell, repository and developer credentials - possibly hours after you installed it. The format needs a permissions manifest, but a manifest alone is not…
❤1
September 7, 2026 473 2