Expert Debunks Chinese Sleeper-Agent Myth, Highlights Real Malicious Skill File Risks
ShakeelHashim · x · 2026-07-29
The recent hacking incident involving Hugging Face has sparked discussions in the AI safety community regarding actual threats. Security expert Zack Korman dismissed claims by some VCs regarding "Chinese sleeper agents" embedded in models, noting that such threats have never occurred and lack evidence.
Instead, he highlighted the tangible risk of supply chain attacks via malicious skill files. Korman revealed he maintains a GitHub repository of skill files containing malicious hooks; if users download and run them (e.g., in Claude Code), their systems get compromised. This suggests that real AI vulnerabilities lie in the abuse of developer tools and components rather than hypothetical model backdoors.
More from coding & agent
- theo builds his own visualizer for today's agent models, showing how cheap Luna really is — ivan_bezdomny · 2026-09-23
- Vite+ Hits RC: One Rust-Powered CLI to Replace Your Entire Web Toolchain — cnakazawa · 2026-09-23
- Tesla's in-car Grok agent books trips across Gmail, Calendar and Notion in one command — xiaohu · 2026-09-23
- Tesla's In-Car Grok Assistant Now Executes Cross-App Tasks in One Sentence — xiaohu · 2026-09-23
- Garry Tan says Capy lets him ship PRs much faster than Codex or Claude Code — garrytan · 2026-09-23
- DeskPilot: open-source native Python desktop client for local LLMs with MCP and sandboxed tools — poofph · 2026-09-23