EngineeringGuide
Before You Install an AI Agent Skill: ESET Found More Than 3,000 Malicious Ones
Skills are the new browser extensions: small packages that teach an AI agent a new job, installed in a minute by whoever needs one. This year a security vendor counted how many of them are hostile. The answer is a reason to treat every skill as installed software, not as a clever prompt.
Author
DueClix Engineering
Published
Reading time
5 min read
A skill is a small package that gives an AI agent a new ability. Anthropic's documentation describes one as instructions, metadata and optional resources such as scripts and templates, which the agent loads when a task looks relevant. Other agent products have their own versions, and public repositories now hold them in the hundreds of thousands. Installing one usually takes a minute and needs nobody's approval.
Between March and May 2026 the security company ESET scanned almost 900,000 unique skills from popular repositories. More than 25,000 were suspicious, and more than 3,000 were outright malicious, "leading to credential theft, data exfiltration and remote code execution." Over the same three months the pool ESET scanned grew from about 60,000 skills to almost 900,000, and the malicious ones from about 600 to more than 3,000. ESET published the numbers in its H1 2026 Threat Report in July and repeated them in its guidance for small businesses on 21 September.
A skill is installed software, not a prompt
A prompt is text you can read before you send it. A skill is different in two ways. Its instructions are loaded by the agent when the agent decides they apply, so you may never see them in the conversation. And its scripts run with whatever access the agent has: your files, your shell, your connected accounts. That is what makes a skill useful, and it is the same property that makes a hostile one dangerous.
The clearest warning comes from a vendor about its own feature. Anthropic's documentation says to "use Skills only from trusted sources: those you created yourself or obtained from Anthropic," warns that malicious ones "could lead to data exfiltration, unauthorized system access, or other security risks," and sums it up in four words: "Treat like installing software." We would take that literally. The agent is a program with your permissions, and a skill is code you are adding to it.
What ESET actually found
The report lists the capabilities its researchers saw in malicious and suspicious skills: command execution, file access, downloading third-party tools, credential loading, code injection and obfuscation. Three findings stand out for a small business:
- Real attack tools inside skills. Some malicious skills bundled hacking tools such as Mimikatz and Impacket, which attackers use to harvest credentials and move between machines on a network.
- Skills that change themselves. ESET found suspicious self-modifying skills capable of creating persistence, meaning they arrange to stay and run again later.
- Security skills that do nothing. Some skills presented as protection were benign but ineffective, which ESET notes can create a false sense of protection. A skill that promises to make your agent safe is still a skill to vet.
The review you did last month does not hold
ESET's September guidance makes a point that is easy to miss: skills and tool connections, including the MCP servers many agents now use, "remain live dependencies." A skill that fetches instructions or code from somewhere else at run time can change after you reviewed it, and ESET describes how a trusted one can turn into an infostealer that way. Anthropic's documentation says the same thing from the other side: "Even trustworthy Skills can be compromised if their external dependencies change over time."
So vetting is not a single event. It is a question you ask when you install a skill and again whenever it, or anything it pulls in, changes.
A vetting checklist for a small team
- Know who wrote it. Prefer skills from the vendor of your agent, or ones you wrote yourself. A popular repository is not a trusted author: ESET's 3,000 malicious skills came from popular repositories.
- Read every file, not the description. The instruction file, every script and anything bundled with it. Look for network calls, file access outside the skill's job, downloads of other tools, and text that is encoded or deliberately hard to read. Obfuscation was one of the markers ESET looked for.
- Check whether it fetches anything when it runs. If it pulls instructions or code from a URL, you are trusting whoever controls that URL on every run. Keep a reviewed copy of your own, or do not install it.
- Match its access to its job. A skill that formats invoices has no reason to run shell commands or read your browser's saved passwords. Run agents that use outside skills where those credentials are not present.
- Treat "security" skills with the same suspicion. A skill cannot vouch for itself.
- Keep a list. Which skills and connectors are installed, on which machines, who approved each one and when it was last read. Remove what nobody uses.
Break the trifecta
ESET's guidance frames the dangerous case for any agent as a "lethal trifecta": access to sensitive data, exposure to material from outside the company, and permission to communicate or take action externally. Remove one of the three and the risk falls sharply. A skill from a public repository is, by definition, material from outside the company. So the agent that runs one should either not hold sensitive data, or not be able to send anything out. We have written about what changes the moment a system can act; skills are the fastest way to change what it can do without anyone deciding to.
The same test applies to how you build: where a capability matters to the business, owning the part that holds your data is often simpler than auditing someone else's package every month.
Put one line in your AI policy
ESET's SMB Cyber Readiness Index 2026 surveyed 4,400 decision-makers at businesses with 25 to 1,000 endpoints and found that 40 percent had no policies restricting shadow AI, the tools staff adopt without anyone signing off. Skills are shadow AI at its smallest: free, instant and invisible to whoever pays for the agent. If your business has no AI policy yet, start with one line: nobody installs an agent skill, plugin or MCP server until a second person has read it. If you already have one, check that it says this.
Browser extensions taught everyone this lesson slowly. Agent skills are moving faster, and they run with more access. The fix is not a product. It is the habit of reading what you install.
Sources
- ESET WeLiveSecurity, Tomáš Foltýn, The SMB cybersecurity squeeze: AI agents at work, old attacks in overdrive, 21 September 2026. The 900,000 / 25,000 / 3,000 figures and their consequences, live dependencies and the rug-pull scenario, the lethal trifecta.
- ESET, H1 2026 Threat Report (covering December 2025 to May 2026). Mimikatz and Impacket, self-modifying skills with persistence, ineffective security skills.
- Help Net Security, Thousands of malicious AI skills found capable of stealing data, running malware, 8 July 2026. Growth from about 60,000 to almost 900,000 skills and from about 600 to more than 3,000 malicious ones; the list of capabilities.
- ESET, ESET SMB Cyber Readiness Index 2026, 2 June 2026. 4,400 SMB decision-makers, 25 to 1,000 endpoints; 40 percent without policies restricting shadow AI.
- Anthropic, Agent Skills overview, security considerations, accessed 30 September 2026. What a skill contains, and the quoted guidance.