Auditing Agent Skills: A Threat Model for the Next Generation of AI Package Managers

TL;DR AI
2 min readKey summary
AI agents can now install reusable skills from GitHub and similar sources, but many are unverified and may hide prompt injections or malicious scripts.
A test skill that looked like a harmless CSV formatter was found to contain covert instructions, showing how easily dangerous content can slip through quick manual review.
Because agents may access files, terminals, and cloud accounts, a compromised skill could manipulate actions or exfiltrate data while appearing benign.
The story frames this as an emerging supply-chain risk for AI tools and argues for stronger verification before broad adoption.
