AgentBaiting uses 600 fake MCP and Skills listings to lure AI assistants
TechNadu · x · 2026-07-21
Researchers say a new attack called AgentBaiting can trick AI assistants such as Claude Code, Gemini, and ChatGPT into recommending malicious Skills and MCP servers. The campaign reportedly seeds more than 600 fake listings in public registries to spread malware, showing how easily agent toolchains can be weaponized.
More from coding & agent
- AI agents are making full UI specs obsolete, so teams should build a “baby” app first — haltakov · 2026-07-21
- LangChain adds structured tracing for Cursor agent sessions in LangSmith — LangChain · 2026-07-21
- Genesys uses a causal graph, not a vector store, for long-term agent memory — StudentSweet3601 · 2026-07-21
- AI speeds up research, but hands-on experience still wins on the details — mushroomsoup20 · 2026-07-21
- A shopping app demo ties OpenTelemetry, Dynatrace and Port into agentic ops — Pavan_Belagatti · 2026-07-21
- A GLP1R variant may explain stronger Ozempic weight loss, and the team built an agent workflow — julia_kiseleva · 2026-07-21