A fake AI agent skill passed every security scanner and reportedly reached 26,000 agents

This article was published on June 23, 2026 The skill carried no malicious code of its own but pointed agents to an external URL the attacker could rewrite at any time after the scan cleared Security firm AIR got a fake skill past every major scanner and says it reached 26,000 agents by swapping an external URL after the scan cleared. Security firm AIR built a fake AI agent skill, pushed it through a popular skill marketplace and promoted it with an Instagram ad, and says it reached roughly 26,000 agents, including some on corporate accounts. Every skill security scanner the firm tested it against marked it safe. The payload was harmless by design, collecting only the user’s email address, but AIR says a real attacker could have used the same foothold to read files, move data, or hit internal systems. The skill, called brand-landingpage, claimed to build a landing page using Google’s Stitch design tool and was aimed at non-technical users. To make it look credible, AIR went after two trust signals that the ecosystem still treats as proof of safety: GitHub stars and a clean scanner verdict. For the stars, it opened a pull request to a skill marketplace repository with around 36,000
Source: For the complete article, please visit the original source link below.



