VulnWatch VulnWatch
← Back to dashboard
Unknown rss_thehackernews · rss_5ab4c1aa49300ecae62dfd79fd50dd8b

SkillCloak Lets Malicious AI Agent Skills Evade Static Scanners with Self-Extracting Packing

Published Jul 6, 2026

Scanners meant to catch malicious add-on "skills" for AI coding agents can be fooled by a few simple changes that leave the malware working, according to a new study from researchers at the Hong Kong University of Science and Technology.

Their strongest trick slipped past every scanner tested more than 90% of the time, and the same team built a runtime checker that catches most of the

Affected AI Products

ai agent
Get the weekly digest. Every Monday: top AI security stories of the week. Free.