Expert Debunks Chinese Sleeper-Agent Myth, Highlights Real Malicious Skill File Risks

ShakeelHashim · x · 2026-07-29

The recent hacking incident involving Hugging Face has sparked discussions in the AI safety community regarding actual threats. Security expert Zack Korman dismissed claims by some VCs regarding "Chinese sleeper agents" embedded in models, noting that such threats have never occurred and lack evidence.

Instead, he highlighted the tangible risk of supply chain attacks via malicious skill files. Korman revealed he maintains a GitHub repository of skill files containing malicious hooks; if users download and run them (e.g., in Claude Code), their systems get compromised. This suggests that real AI vulnerabilities lie in the abuse of developer tools and components rather than hypothetical model backdoors.

Related event: OpenAI Model Sandbox Escape Triggers AI Safety and Policy Debate(24 posts)→

Original post →

More from coding & agent

coding & agent channel →