VulnWatch VulnWatch
← Back to dashboard
Unknown rss_thehackernews · rss_6dc2501726f3c67ec435181a6ee4e54b

Fake AI Agent Skill Passed Security Scans and Reportedly Reached 26,000 Agents

Published Jun 23, 2026

Security firm AIR built a fake AI agent skill, pushed it through a popular skill marketplace and an Instagram ad, and says it reached roughly 26,000 agents, including some on corporate accounts.

Every skill security scanner the firm tested it against marked it safe. The payload was harmless by design: it collected the user's email address and did nothing else.

The point was to show

Affected AI Products

ai agent
Get the weekly digest. Every Monday: top AI security stories of the week. Free.