Shared Agent Skill Libraries Propagate Malware, 41.8% Self-Poisoning Rate Found

omarsar0 · x · 2026-08-27

New research reveals that shared skill libraries for coding agents, often treated as safe for reuse, can propagate malware. The EvoMal attack plants a malicious skill in a library; agents retrieve it as an authoring template, write new skills preserving the payload, and execute them. This "author-style copying" causes exponential spread of malicious skills.

Original post →

More from coding & agent

coding & agent channel →