Skip to content
Artwork for AI Security Ops
AI Security Ops · Yesterday · 11 min

Agentic Skills | Episode 69

Agentic skills can make AI agents more capable and consistent—but they can also introduce serious security risks. This episode explains how skills work, why malicious skills rank as a leading OWASP concern, and how seemingly harmless Markdown instructions can enable credential theft, remote payload delivery, and manipulated recommendations. Real-world examples illustrate how malicious skills can evade scanners and exploit trusted marketplaces. The episode concludes with practical safeguards, including reviewing skill files, watching for external instructions and prompt injection, pinning versions, limiting permissions, and running agents inside isolated environments. Links: OWASP Agentic Skills Top 10 Malicious AI Agent Skill Bypasses Security Scans and Seizes Full Control of Over 26,000 Agents (00:00) - Agentic Skills and the OWASP Top 10 (00:23) - Podcast Sponsors: BHIS and Antisyphon Training (01:29) - What Is an Agentic Skill? (03:13) - Skill Marketplaces and Widespread Adoption (03:46) - Why Malicious Skills Are the #1 Risk (05:50) - Remote Payloads and External Instructions (07:00) - Malicious Skill Takes Control of 26,000 Agents (08:09) - Money Radar and Manipulated Recommendations (09:20) - How to Evaluate and Use Skills Safely (11:08) - Closing Thoughts Click here to watch this episode on YouTube. Creators & Guests Brian Fehrman - Host Brought to you by: Black Hills Information Security https://www.blackhillsinfosec.com ☯️ Introducing BHIS Fusion Penetration Testing https://www.blackhillsinfosec.com/fusion-penetration-testing/ Antisyphon Training https://www.antisyphontraining.com/ Active Countermeasures https://www.activecountermeasures.com Wild West Hackin Fest https://wildwesthackinfest.com 🔗 Register for FREE Infosec Webcasts, Anti-casts & Summits https://poweredbybhis.com Click here to view the episode transcript.

0:00 · Agentic Skills and the OWASP Top 10-11:28

transcript

No transcript — this publisher did not publish one.

show notes

Agentic skills can make AI agents more capable and consistent—but they can also introduce serious security risks. This episode explains how skills work, why malicious skills rank as a leading OWASP concern, and how seemingly harmless Markdown instructions can enable credential theft, remote payload delivery, and manipulated recommendations. Real-world examples illustrate how malicious skills can evade scanners and exploit trusted marketplaces. The episode concludes with practical safeguards, including reviewing skill files, watching for external instructions and prompt injection, pinning versions, limiting permissions, and running agents inside isolated environments.

Links:
OWASP Agentic Skills Top 10
Malicious AI Agent Skill Bypasses Security Scans and Seizes Full Control of Over 26,000 Agents

  • (00:00) - Agentic Skills and the OWASP Top 10
  • (00:23) - Podcast Sponsors: BHIS and Antisyphon Training
  • (01:29) - What Is an Agentic Skill?
  • (03:13) - Skill Marketplaces and Widespread Adoption
  • (03:46) - Why Malicious Skills Are the #1 Risk
  • (05:50) - Remote Payloads and External Instructions
  • (07:00) - Malicious Skill Takes Control of 26,000 Agents
  • (08:09) - Money Radar and Manipulated Recommendations
  • (09:20) - How to Evaluate and Use Skills Safely
  • (11:08) - Closing Thoughts

Click here to watch this episode on YouTube.

Creators & Guests

Brought to you by:

Black Hills Information Security 

https://www.blackhillsinfosec.com


☯️ Introducing BHIS Fusion Penetration Testing
https://www.blackhillsinfosec.com/fusion-penetration-testing/

Antisyphon Training

https://www.antisyphontraining.com/


Active Countermeasures

https://www.activecountermeasures.com


Wild West Hackin Fest

https://wildwesthackinfest.com

🔗 Register for FREE Infosec Webcasts, Anti-casts & Summits
https://poweredbybhis.com

Click here to view the episode transcript.

links11

chapters

10 chapters