Audited 50+ AI agent skills, and most had dangerous command-execution risks
aiz27 · reddit · 2026-07-27
The authors audited 50+ open-source AI agent skills and SKILL.md packages and found common security issues, especially because agents can turn markdown instructions into real terminal commands.
They released SkillShield, a free open-source tool that scans skills before execution across 11 security axes, including prompt injection, risky install steps like curl | bash, untrusted registries/submodules, and overly broad file/network permissions.
Users can paste a raw SKILL.md, upload a package, or submit a GitHub repo URL to get a pre-flight report. The repo is public at github.com/adnan-iz/ai-skill-shield.
More from coding & agent
- Cursor should add a direct Grok Build backend, says a new ACP integration proposal — Daniel_Farinax · 2026-07-27
- Berkeley’s ABBEL trains agents to store graded belief states instead of full history — berkeley_ai · 2026-07-27
- AI Stupid Level says it tracks silent model drift across 20+ providers and 98,000 MAU — ionutvi · 2026-07-27
- Browser-agent builder asks whether website drift still breaks self-healing workflows — ryicean · 2026-07-27
- Testing Claude to Automate B2B Lead Gen and Booking — petewoodbridge · 2026-07-27
- BrowserSmith automates four ChatGPT tabs to plan, write, review and run real apps — SouthernArcher9793 · 2026-07-27