分析3984个AI技能发现76个恶意程序,揭示代理生态安全威胁。
Technical Report: Exploring the Emerging Threats of the Agent Skill Ecosystem

- 从市场数据中提取真实样本构建威胁分类体系
- 13.4%技能含高危漏洞,8个恶意技能仍公开可用
- 为开发者与平台提供自动化安全检测必要性依据
我们分析了来自主要市场平台的3,984个AI代理技能,发现76个已确认的恶意载荷,包括凭据窃取、后门植入和数据外泄。13.4%的技能至少包含一个高危安全问题,且截至发表日期,仍有至少8个手动确认的恶意技能在clawhub.ai上公开可获取。本报告详细描述了研究方法,基于真实样本提出了威胁分类框架,并总结了观察到的攻击模式。随着技能市场快速扩张,AI代理逐步获得对敏感凭证与系统的访问权限,自动化安全分析已不再可选。
原文摘要 · Abstract (English)
We analyzed 3,984 AI agent skills from major marketplaces and found 76 confirmed malicious payloads, including credential theft, backdoor installation, and data exfiltration. 13.4% of all skills contain at least one critical-level security issue and at least 8 manually confirmed malicious skills remain publicly available on clawhub.ai as of the date of publication. This report documents our methodology, presents a threat taxonomy based on real-world samples, and details the attack patterns we observed. As skill marketplaces grow rapidly and AI agents gain access to sensitive credentials and systems, automated security analysis is no longer optional.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。