{"slug": "agent-scan-skill-inspector", "title": "Agent Scan Skill Inspector", "summary": "Snyk released Agent Scan's Skill Inspector, a free tool that scans AI agent skills and MCP servers for malicious code and security vulnerabilities, after analyzing nearly 4,000 agent skills across major marketplaces and finding credential theft, backdoor installation, and data exfiltration. Snyk reported that 91% of confirmed malicious skills employ prompt injection techniques and 100% contain malicious code patterns. The CLI auto-discovers agents, MCP servers, and skills across Claude Code/Desktop, Cursor, Gemini CLI, and Windsurf, with MDM-based enterprise deployment available through Snyk's EVO platform.", "body_md": "# Agent ScanSkill Inspector\n\nOur analysis of nearly 4,000 agent skills across major marketplaces uncovered credential theft, backdoor installation, and data exfiltration hidden in publicly available skills.\n\nWe are providing Agent Scan's Skill Inspector as a tool to the community so anyone can check both for **malicious skills** and for **security vulnerabilities** in their skills before installing them.\n\n## Skill Inspector\n\n[terms of service](https://github.com/snyk/agent-scan/blob/main/TERMS.md).\n\n## Scan with the CLI\n\nUse **Snyk Agent Scan**'s CLI to scan agent skills and MCP servers directly on your machine. It auto-discovers agents, MCP servers, and skills across Claude Code/Desktop, Cursor, Gemini CLI, and Windsurf.\n\nTo get started, run this command:\n\nThe CLI allows you to scan your agent's supply chain in a local or enterprise environment:\n\nDiscovery and supply chain scanning across your agent deployments by scanning agents, MCP servers, and skills, detecting prompt injection, tool poisoning, cross-origin escalation, and toxic flows.\n\nSupport for MDM-based deployment of Agent Scan with full observability on [Snyk's EVO](https://evo.ai.snyk.io/) platform. [Contact us](https://evo.ai.snyk.io/#contact-us) to get started with enterprise rollout.\n\n## Learn about Skill Security\n\nAgent skills can come with many security risks. Our [research](https://github.com/snyk/agent-scan/blob/main/.github/reports/skills-report.pdf) has shown recurring issues such as prompt injection, malicious code, secret exposure, and risky external dependencies are common in the wild. We identify the following common risks:\n\nHidden or deceptive instructions outside of the stated purpose of the skill.\n\nDetects hidden instructions in obfuscated formats (base64, Unicode, other languages), \"ignore previous instruction\" statements, system message impersonation, and data exfiltration attempts. 91% of confirmed malicious skills employ prompt injection techniques.\n\nBackdoors, data exfiltration, RCE, and supply chain attacks in skill scripts and code.\n\nDetects credential theft patterns in scripts, typosquatted package names, executables requiring elevated privileges, and malware installation patterns. 100% of confirmed malicious skills contain malicious code patterns.\n\nDownloads from potentially malicious sources that could distribute malware.\n\nDetects downloads from unknown or untrusted domains, GitHub releases from unfamiliar users, ZIP archives with passwords, and external platform links requesting untrusted software installation.\n\nInsecure handling of sensitive credentials that could lead to exfiltration.\n\nDetects instructions to echo or print API keys, embedding credentials in generated commands, requesting users to share secrets in outputs, and insecure credential storage patterns.\n\nHardcoded secrets, API keys, and credentials embedded directly in skill files.\n\nDetects hardcoded API keys, embedded passwords, authentication tokens, private keys, and encrypted archive passwords that may be accidentally leaked or deliberately embedded.\n\nProcessing of untrusted external content that permits indirect prompt injection.\n\nDetects web browsing and API consumption which can introduce hidden instructions by third party malicious actors (a social media post, website content). Third-party content exposure increases the risk of external interference, even if the skill itself can be considered benign.\n\nExternal URLs, Git repositories or skill dependencies that cannot be verified as part of the skill itself.\n\nDetects runtime downloads (curl | bash patterns), external links, git repositories and configuration files fetched from remote servers. The published skill may appear benign as-is, but may link to additional resources and software packages that can compromise the agent at runtime.\n\nSkills with direct access to financial accounts, trading platforms, or payment systems.\n\nDetects skills operating cryptocurrency, analyzing recurring payments, direct access to bank accounts, and trading platform automation. While not inherently malicious, skills with financial access warrant extra scrutiny.\n\nSkills that prompt the agent to compromise the security or integrity of the user's machine.\n\nDetects modifications to systemctl service files, critical system files, security configurations, installation of persistent backdoor programs, and disabling of security measures.", "url": "https://wpnews.pro/news/agent-scan-skill-inspector", "canonical_source": "https://labs.snyk.io/experiments/skill-scan/", "published_at": "2026-09-12 15:57:27+00:00", "updated_at": "2026-09-12 16:17:19.279640+00:00", "lang": "en", "topics": ["ai-agents", "ai-safety", "ai-tools", "developer-tools", "ai-products"], "entities": ["Snyk", "Agent Scan", "Skill Inspector", "Claude Code", "Cursor", "Gemini CLI", "Windsurf", "Snyk EVO"], "alternates": {"html": "https://wpnews.pro/news/agent-scan-skill-inspector", "markdown": "https://wpnews.pro/news/agent-scan-skill-inspector.md", "text": "https://wpnews.pro/news/agent-scan-skill-inspector.txt", "jsonld": "https://wpnews.pro/news/agent-scan-skill-inspector.jsonld"}}