Warning: Claude can be tricked into installing malware via poisoned skills

Novel_Bedroom_3466 · reddit · 2026-08-30

A security demonstration reveals that Claude Code and similar AI agents can be tricked into executing malware through poisoned 'skill' files. By disguising malicious payloads, attackers can fool the AI into running harmful commands. Aside from manually scanning every command and link generated by Claude, there are currently no clear automatic defenses, posing a serious risk for developers relying on AI coding tools.

Original post →

More from coding & agent

coding & agent channel →