{"id":6161,"date":"2026-09-24T13:17:31","date_gmt":"2026-09-24T13:17:31","guid":{"rendered":"https:\/\/adex.com\/blog\/?p=6161"},"modified":"2026-09-24T13:22:03","modified_gmt":"2026-09-24T13:22:03","slug":"ai-agent-attackers-delivery-boy","status":"publish","type":"post","link":"https:\/\/adex.com\/blog\/ai-agent-attackers-delivery-boy\/","title":{"rendered":"Do Not Mention This to the User: How an AI Agent Can Turn Into the Attacker&#8217;s Delivery Boy"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">In July 2026, <a href=\"https:\/\/www.island.io\/blog\/agentbaiting-how-800-fake-ai-skills-and-mcp-servers-delivered-malware\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Island published a study of a campaign called FakeGit<\/a>: the researchers report that they found roughly 7,600 fake GitHub repositories from 6,600 fake profiles, with more than 14 million downloads. Over 800 of them posed as AI Skills and MCP servers. Inside were the SmartLoader downloader and the StealC infostealer.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Fake repositories are not a sensation, so what was the study supposed to show?<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">A new mark: it was not a person or a simple Google search, but in the test described in the report, Gemini and ChatGPT independently recommended the same fake <strong>walmart-mcp<\/strong>. The agents found the attacker&#8217;s repo and handed the user instructions for installing malware. The package borrowed Walmart&#8217;s name, and on the researcher\u2019s account, Walmart had no involvement in it, and its own systems and services were not affected.<\/p>\n\n\n<div class=\"block__bord\"><div class=\"block__bord_desc\"><p>This is why we call it a new mark: before, malicious actors needed to trick a person. Today, they trick the assistant instead: you ask what tool to use, the agent answers in good faith, and you skip the check because your buddy the agent would never.\u00a0<\/p>\n<\/div><\/div>\n<style>\n.block__bord { margin: 32px 0; padding: 1.25em 2.375em;\tborder-radius: 24px; background: rgba(0, 220, 200, 0.20); }\n.block__bord_desc {font-size: 16px !important;font-weight: 400 !important;color: #606060 !important;}\n<\/style>\n\n\n\n<p class=\"wp-block-paragraph\">Now imagine someone put a \u2018<em>do not mention this to the user<\/em>\u2019 line inside that new skill or MCP, and the agent follows it obediently. Sounds like a creepy story, but it\u2019s real, subject to the report below, and looks disturbing.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">None of this means throwing your agent out, though. We went through the incidents seen in the wild and the proof-of-concept research behind them, and asked <a href=\"https:\/\/www.linkedin.com\/in\/%D1%81%D0%B5%D1%80%D0%B3%D0%B5%D0%B9-%D0%BC%D0%B0%D1%80%D1%82%D1%8C%D1%8F%D0%BD%D0%BE%D0%B2-25945391\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Sergey Martianov, CPO, ADEX<\/a>, where the real dangers are and what reduces the risk.<\/p>\n\n\n<div class=\"toc\"><h4 class=\"toc__title\" id=\"contents\">Contents<\/h4><ul class=\"toc__list\"><li class=\"toc__list_item\"><a href=\"#how-does-an-agent-end-up-recommending-malware\">How Does an Agent End Up Recommending Malware?<\/a><\/li><li class=\"toc__list_item\"><a href=\"#agentbaiting-the-agent-recommends-you-malware\">AgentBaiting: The Agent Recommends You Malware<\/a><\/li><li class=\"toc__list_item\"><a href=\"#tool-poisoning-the-agent-follows-an-order-hidden-in-what-it-reads\">Tool Poisoning: The Agent Follows an Order Hidden in What It Reads<\/a><\/li><li class=\"toc__list_item\"><a href=\"#the-agent-hides-what-it-did\">The Agent Hides What It Did<\/a><\/li><li class=\"toc__list_item\"><a href=\"#rugpull-when-the-agent-becomes-the-leak\">RugPull: When The Agent Becomes the Leak<\/a><\/li><li class=\"toc__list_item\"><a href=\"#the-swap-can-happen-outside-the-package\">The Swap Can Happen Outside the Package<\/a><\/li><li class=\"toc__list_item\"><a href=\"#opening-someones-project-can-run-their-code\">Opening Someone&#039;s Project Can Run Their Code<\/a><\/li><li class=\"toc__list_item\"><a href=\"#clickfix-when-a-user-installs-malware-deliberately\">ClickFix: When A User Installs Malware Deliberately<\/a><\/li><li class=\"toc__list_item\"><a href=\"#the-agent-as-the-weapon\">The Agent as the Weapon<\/a><\/li><li class=\"toc__list_item\"><a href=\"#the-economics-of-fake-reputation\">The Economics of Fake Reputation<\/a><\/li><li class=\"toc__list_item\"><a href=\"#why-simply-reading-a-code-doesnt-help\">Why Simply Reading a Code Doesn\u2019t Help?<\/a><\/li><li class=\"toc__list_item\"><a href=\"#summary-how-to-protect-your-agent-before-you-install-any-skills-and-files\">Summary: How to Protect Your Agent Before You Install Any Skills and Files<\/a><\/li><li class=\"toc__list_item\"><a href=\"#where-this-leaves-you\">Where This Leaves You<\/a><\/li><\/ul><\/div><style>\n.toc {}\n.toc__title {\n      font-size: 32px;\n    line-height: 40px;\n    font-weight: 700;\n}\n.toc__list_item {\n    color: #FE645A !important;\n}\n.toc__list_item:not(:last-child){\n    margin-bottom: 5px;\n}\n.toc__list_item a {\n    font-size: 18px;\n    line-height: 24px;\n    color: #FE645A;\n    font-weight: 600;\n}\n.toc__list_item a:hover {\n    text-decoration: underline;\n}\n@media (max-width: 1023px) {.toc__title {font-size: 24px;line-height: 32px;}}\n<\/style>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"how-does-an-agent-end-up-recommending-malware\">How Does an Agent End Up Recommending Malware?<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Almost all the case studies we\u2019ll describe below are possible for two reasons, and both of them are simply how agents are built:<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Reason 1. Everything arrives as text<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">A regular program keeps the commands it runs separate from the files it opens. A document you open in Word will never become an order to Word, no matter what you type inside it.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">AI models basically know the difference, can tell which words are yours and which came from a file it opened, and are trained to listen to you first. However, nothing stops a sentence in a README from working like an order, so if it is written well enough, the agent can follow it as well.<\/p>\n\n\n<div class=\"block__bord\"><div class=\"block__bord_desc\"><p><strong>This trick is called prompt injection. When the instruction is hidden inside a file the agent reads for you, it is indirect prompt injection. It does not fire every time, but \u2018bad\u2019 instructions have all chances to look exactly like good ones once.<\/strong><\/p>\n<\/div><\/div>\n<style>\n.block__bord { margin: 32px 0; padding: 1.25em 2.375em;\tborder-radius: 24px; background: rgba(0, 220, 200, 0.20); }\n.block__bord_desc {font-size: 16px !important;font-weight: 400 !important;color: #606060 !important;}\n<\/style>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Reason 2. The agent can actually do it<\/strong><\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Any injected instruction is harmless on its own: it needs a combination. <a href=\"https:\/\/simonwillison.net\/2025\/Jun\/16\/the-lethal-trifecta\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Simon Willison named the lethal trifecta<\/a>: three conditions meeting inside one agent:<\/p>\n\n\n\n<ul class=\"wp-block-list has-cyan-bluish-gray-background-color has-background\">\n<li>It <strong>sees something valuable (your files, your keys, your mail)<\/strong><\/li>\n\n\n\n<li>It <strong>reads something from outside that you do not control<\/strong><\/li>\n\n\n\n<li>It <strong>can send something out<\/strong><\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">All three at once, and you can be robbed, but take away any one of them, and the instruction just sits in the file doing nothing.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">That explains three of the cases below: Tool Poisoning, the skill that tells the agent not to mention what it did, and GTG-1002, where the model was talked into treating an attack as an authorized test.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The other five don&#8217;t need the model to be fooled at all \u2013 they need a human, or an agent doing a plain web search, to trust a fake signal: a repository built to look trusted, a package that was honest for fifteen versions, a link that only turns malicious once the install count climbs, a settings file nobody re-approves after the first look. Stars, forks, and download counts get faked in the same way any other popularity metric can be faked&nbsp; \u2013&nbsp; the difference is that here, the reward for faking them is code execution, not a sale.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Now, eight ways your agent can hand you malware without ever meaning to.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Note:<\/strong> No vendor can fix both once and for all, and it\u2019s not about incompetence. We have been here before with SQL injection, where an attacker typed a piece of a database command into a name field, and the database ran it. That one got fixed: instead of pasting whatever the user typed into the command, the program now sends the command and the data separately, so the data can never become part of the command. Nobody lost anything, because running data as code was never a feature.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Meanwhile, with an agent, it is exactly the feature: following instructions written in ordinary words is the whole job, so there is no way to switch that off for bad instructions, because they look exactly like good ones: same words, same language, same stream of text.<\/p>\n\n\n\n<style>\n.adexvz-11 {\n  --az-ink: #0b0f1c;\n  --az-body: #2a3347;\n  --az-mute: #5b6a8a;\n  --az-faint: #8896b3;\n  --az-line: #dde3ee;\n  --az-hair: #eef1f7;\n  --az-bg: #f7f9fc;\n  --az-tint: #fafbff;\n  --az-teal: #00c9b8;\n  --az-blue: #3b5bdb;\n  --az-red: #e03355;\n\n  display: block !important;\n  width: 100% !important;\n  max-width: 660px !important;\n  margin: 32px auto !important;\n  padding: 24px 20px 18px !important;\n  color: var(--az-body) !important;\n  background: var(--az-bg) !important;\n  border: 1px solid var(--az-line) !important;\n  border-radius: 12px !important;\n  font-family: \"Inter\", -apple-system, BlinkMacSystemFont, \"Segoe UI\", Roboto, Arial, sans-serif !important;\n  text-align: left !important;\n  box-sizing: border-box !important;\n  -webkit-font-smoothing: antialiased;\n}\n\n.adexvz-11 *,\n.adexvz-11 *::before,\n.adexvz-11 *::after {\n  box-sizing: border-box !important;\n}\n\n.adexvz-11 .az-head {\n  display: flex !important;\n  align-items: center !important;\n  gap: 10px !important;\n  margin: 0 0 18px !important;\n}\n\n.adexvz-11 .az-logo {\n  display: block !important;\n  flex: 0 0 auto !important;\n  width: 24px !important;\n  height: 28px !important;\n}\n\n.adexvz-11 .az-title {\n  margin: 0 !important;\n  padding: 0 !important;\n  border: 0 !important;\n  color: var(--az-ink) !important;\n  font-family: inherit !important;\n  font-size: 16px !important;\n  font-weight: 700 !important;\n  line-height: 1.3 !important;\n  letter-spacing: -0.01em !important;\n}\n\n.adexvz-11 .az-sub {\n  margin: 2px 0 0 !important;\n  color: var(--az-faint) !important;\n  font-size: 12px !important;\n  font-weight: 400 !important;\n  line-height: 1.4 !important;\n}\n\n.adexvz-11 .az-table-wrap {\n  width: 100% !important;\n  overflow: hidden !important;\n  background: #ffffff !important;\n  border: 1px solid var(--az-line) !important;\n  border-radius: 10px !important;\n}\n\n.adexvz-11 table {\n  width: 100% !important;\n  min-width: 0 !important;\n  margin: 0 !important;\n  background: transparent !important;\n  border: 0 !important;\n  border-collapse: collapse !important;\n  border-spacing: 0 !important;\n  table-layout: fixed !important;\n  font-family: inherit !important;\n  font-size: 12px !important;\n}\n\n.adexvz-11 col.az-c1 {\n  width: 26% !important;\n}\n\n.adexvz-11 col.az-c2 {\n  width: 34% !important;\n}\n\n.adexvz-11 col.az-c3 {\n  width: 40% !important;\n}\n\n.adexvz-11 thead th {\n  padding: 11px 14px !important;\n  color: var(--az-mute) !important;\n  background: #f0f2f8 !important;\n  border: 0 !important;\n  border-bottom: 2px solid var(--az-line) !important;\n  font-family: inherit !important;\n  font-size: 10px !important;\n  font-weight: 700 !important;\n  line-height: 1.4 !important;\n  letter-spacing: 0.07em !important;\n  text-align: left !important;\n  text-transform: uppercase !important;\n  vertical-align: bottom !important;\n}\n\n.adexvz-11 thead th:not(:last-child) {\n  border-right: 1px solid var(--az-line) !important;\n}\n\n.adexvz-11 thead .az-h1 {\n  border-top: 3px solid var(--az-faint) !important;\n}\n\n.adexvz-11 thead .az-h2 {\n  border-top: 3px solid var(--az-teal) !important;\n}\n\n.adexvz-11 thead .az-h3 {\n  border-top: 3px solid var(--az-red) !important;\n}\n\n.adexvz-11 tbody tr {\n  background: transparent !important;\n  border-bottom: 1px solid var(--az-line) !important;\n}\n\n.adexvz-11 tbody tr:last-child {\n  border-bottom: 0 !important;\n}\n\n.adexvz-11 tbody th,\n.adexvz-11 tbody td {\n  padding: 14px !important;\n  color: var(--az-body) !important;\n  border: 0 !important;\n  font-family: inherit !important;\n  font-size: 12px !important;\n  font-weight: 400 !important;\n  line-height: 1.55 !important;\n  overflow-wrap: anywhere !important;\n  text-align: left !important;\n  vertical-align: top !important;\n}\n\n.adexvz-11 tbody th:not(:last-child),\n.adexvz-11 tbody td:not(:last-child) {\n  border-right: 1px solid var(--az-hair) !important;\n}\n\n.adexvz-11 .az-sig {\n  background: var(--az-tint) !important;\n}\n\n.adexvz-11 .az-ok {\n  color: #0a5c55 !important;\n  background: #fafefd !important;\n}\n\n.adexvz-11 .az-bad {\n  color: #7a1530 !important;\n  background: #fffbfc !important;\n}\n\n.adexvz-11 .az-ico {\n  display: flex !important;\n  align-items: center !important;\n  justify-content: center !important;\n  width: 28px !important;\n  height: 28px !important;\n  margin: 0 0 7px !important;\n  background: #eef2ff !important;\n  border-radius: 7px !important;\n}\n\n.adexvz-11 .az-ico svg {\n  display: block !important;\n  width: 15px !important;\n  height: 15px !important;\n  fill: none !important;\n  stroke: var(--az-blue) !important;\n  stroke-width: 1.7 !important;\n  stroke-linecap: round !important;\n  stroke-linejoin: round !important;\n}\n\n.adexvz-11 .az-name {\n  color: var(--az-ink) !important;\n  font-size: 12px !important;\n  font-weight: 700 !important;\n  line-height: 1.35 !important;\n}\n\n.adexvz-11 .az-lead {\n  display: block !important;\n  margin: 0 0 3px !important;\n  font-weight: 700 !important;\n  letter-spacing: 0.02em !important;\n}\n\n.adexvz-11 tr.az-key th,\n.adexvz-11 tr.az-key td {\n  background: #f5fffd !important;\n}\n\n.adexvz-11 tr.az-key .az-sig {\n  background: #ebf9f6 !important;\n}\n\n.adexvz-11 tr.az-key .az-bad {\n  background: #fff6f8 !important;\n}\n\n.adexvz-11 tr.az-key .az-name {\n  color: #007a6e !important;\n}\n\n.adexvz-11 tr.az-key .az-ico {\n  background: #d0f5ef !important;\n}\n\n.adexvz-11 tr.az-key .az-ico svg {\n  stroke: #007a6e !important;\n}\n\n.adexvz-11 .az-foot {\n  display: flex !important;\n  flex-wrap: wrap !important;\n  align-items: center !important;\n  gap: 10px 16px !important;\n  margin: 14px 0 0 !important;\n  padding: 12px 2px 0 !important;\n  border-top: 1px solid var(--az-line) !important;\n}\n\n.adexvz-11 .az-leg {\n  display: flex !important;\n  align-items: center !important;\n  gap: 6px !important;\n  color: var(--az-faint) !important;\n  font-size: 11px !important;\n  line-height: 1.4 !important;\n}\n\n.adexvz-11 .az-bar {\n  display: block !important;\n  flex: 0 0 auto !important;\n  width: 12px !important;\n  height: 3px !important;\n  border-radius: 2px !important;\n}\n\n.adexvz-11 .az-src {\n  margin-left: auto !important;\n  color: #9ba6b8 !important;\n  font-size: 10px !important;\n  line-height: 1.4 !important;\n  letter-spacing: 0.03em !important;\n}\n\n.adexvz-11 .az-src a {\n  color: #72819d !important;\n  border-bottom: 1px solid rgba(114, 129, 157, 0.5) !important;\n  font-family: inherit !important;\n  font-size: inherit !important;\n  font-weight: inherit !important;\n  text-decoration: none !important;\n}\n\n.adexvz-11 .az-src a:hover {\n  color: #007a6e !important;\n}\n\n@media (max-width: 600px) {\n  .adexvz-11 {\n    padding: 18px 14px 14px !important;\n  }\n\n  .adexvz-11 .az-head {\n    align-items: flex-start !important;\n  }\n\n  .adexvz-11 .az-table-wrap {\n    background: transparent !important;\n    border: 0 !important;\n    border-radius: 0 !important;\n  }\n\n  .adexvz-11 table,\n  .adexvz-11 tbody,\n  .adexvz-11 tbody tr,\n  .adexvz-11 tbody th,\n  .adexvz-11 tbody td {\n    display: block !important;\n    width: 100% !important;\n  }\n\n  .adexvz-11 colgroup,\n  .adexvz-11 thead {\n    display: none !important;\n  }\n\n  .adexvz-11 tbody tr {\n    margin: 0 0 12px !important;\n    overflow: hidden !important;\n    background: #ffffff !important;\n    border: 1px solid var(--az-line) !important;\n    border-radius: 9px !important;\n  }\n\n  .adexvz-11 tbody tr:last-child {\n    margin-bottom: 0 !important;\n  }\n\n  .adexvz-11 tbody th,\n  .adexvz-11 tbody td {\n    border-right: 0 !important;\n    border-bottom: 1px solid var(--az-hair) !important;\n  }\n\n  .adexvz-11 tbody td:last-child {\n    border-bottom: 0 !important;\n  }\n\n  .adexvz-11 tbody th {\n    display: flex !important;\n    align-items: center !important;\n    gap: 10px !important;\n    padding: 12px 14px !important;\n  }\n\n  .adexvz-11 .az-ico {\n    flex: 0 0 auto !important;\n    margin: 0 !important;\n  }\n\n  .adexvz-11 tbody td {\n    padding: 34px 14px 13px !important;\n    position: relative !important;\n  }\n\n  .adexvz-11 tbody td::before {\n    content: attr(data-label);\n    position: absolute !important;\n    top: 10px !important;\n    left: 14px !important;\n    color: var(--az-mute) !important;\n    font-size: 9px !important;\n    font-weight: 700 !important;\n    line-height: 1.2 !important;\n    letter-spacing: 0.07em !important;\n    text-transform: uppercase !important;\n  }\n\n  .adexvz-11 .az-foot {\n    align-items: flex-start !important;\n  }\n\n  .adexvz-11 .az-src {\n    flex-basis: 100% !important;\n    margin-left: 0 !important;\n  }\n}\n<\/style>\n\n<div class=\"adexvz-11\">\n  <div class=\"az-head\">\n    <svg class=\"az-logo\" viewBox=\"0 0 34 40\" fill=\"none\" aria-hidden=\"true\" focusable=\"false\">\n      <path d=\"M5.31 32.14L17.23 39l11.92-6.87L17.23 20 5.31 32.14ZM4.57 28.5l10.36-10.84-2.77-2.84L4.57 28.5ZM19.55 17.62l10.33 10.88-5.91-10.47 2.47-2.51 7.15 14.04.85-.5V9.19l-4.23-2.45L19.55 17.62ZM15.93 0L0 9.19V29.06l.85.5 10.44-19.48 5.96 6.15 3.32-3.47L17.23 5.48l-1.65 3.01-2.62-2.69L15.93 0ZM18.53 0l4.64 9.08 3.97-4.12L18.53 0Z\" fill=\"#00C9B8\"\/>\n    <\/svg>\n\n    <div>\n      <p class=\"az-title\">Where the Wall Is Missing<\/p>\n      <p class=\"az-sub\">A normal program keeps commands and data apart by force. An agent has one input, and everything arrives as text.<\/p>\n    <\/div>\n  <\/div>\n\n  <div class=\"az-table-wrap\">\n    <table aria-label=\"Comparison of ordinary programs and AI agents\">\n      <colgroup>\n        <col class=\"az-c1\">\n        <col class=\"az-c2\">\n        <col class=\"az-c3\">\n      <\/colgroup>\n\n      <thead>\n        <tr>\n          <th class=\"az-h1\" scope=\"col\">What Differs<\/th>\n          <th class=\"az-h2\" scope=\"col\">Ordinary Program<\/th>\n          <th class=\"az-h3\" scope=\"col\">AI Agent<\/th>\n        <\/tr>\n      <\/thead>\n\n      <tbody>\n        <tr>\n          <th class=\"az-sig\" scope=\"row\">\n            <div class=\"az-ico\">\n              <svg viewBox=\"0 0 24 24\" aria-hidden=\"true\">\n                <path d=\"M3 8h13\"\/>\n                <path d=\"M13 5l3 3-3 3\"\/>\n                <path d=\"M21 16H8\"\/>\n                <path d=\"M11 13l-3 3 3 3\"\/>\n              <\/svg>\n            <\/div>\n            <div class=\"az-name\">Input channels<\/div>\n          <\/th>\n          <td class=\"az-ok\" data-label=\"Ordinary Program\">\n            <span class=\"az-lead\">Two<\/span>\n            Code it runs, and data it processes.\n          <\/td>\n          <td class=\"az-bad\" data-label=\"AI Agent\">\n            <span class=\"az-lead\">One<\/span>\n            Text. Your task and the file it was asked to read arrive the same way.\n          <\/td>\n        <\/tr>\n\n        <tr>\n          <th class=\"az-sig\" scope=\"row\">\n            <div class=\"az-ico\">\n              <svg viewBox=\"0 0 24 24\" aria-hidden=\"true\">\n                <path d=\"M4 6h8a5 5 0 0 1 5 5v6\"\/>\n                <path d=\"M14 14l3 3 3-3\"\/>\n              <\/svg>\n            <\/div>\n            <div class=\"az-name\">Can data turn into a command<\/div>\n          <\/th>\n          <td class=\"az-ok\" data-label=\"Ordinary Program\">\n            <span class=\"az-lead\">No<\/span>\n            A document you type into never becomes an order to Word. Executable content is a separate, deliberately gated thing.\n          <\/td>\n          <td class=\"az-bad\" data-label=\"AI Agent\">\n            <span class=\"az-lead\">Yes<\/span>\n            A line in a README can be followed like an instruction.\n          <\/td>\n        <\/tr>\n\n        <tr>\n          <th class=\"az-sig\" scope=\"row\">\n            <div class=\"az-ico\">\n              <svg viewBox=\"0 0 24 24\" aria-hidden=\"true\">\n                <path d=\"M3.2 12.4l9-9H20v7.6l-9 9z\"\/>\n                <circle cx=\"16.2\" cy=\"7.8\" r=\"1.3\"\/>\n              <\/svg>\n            <\/div>\n            <div class=\"az-name\">How your instruction is told from someone else\u2019s<\/div>\n          <\/th>\n          <td class=\"az-ok\" data-label=\"Ordinary Program\">\n            By the channel it came in on. The separation is enforced.\n          <\/td>\n          <td class=\"az-bad\" data-label=\"AI Agent\">\n            The model can see where text came from and is trained to put you first. That is a habit, and a convincing enough line still wins.\n          <\/td>\n        <\/tr>\n\n        <tr>\n          <th class=\"az-sig\" scope=\"row\">\n            <div class=\"az-ico\">\n              <svg viewBox=\"0 0 24 24\" aria-hidden=\"true\">\n                <rect x=\"4\" y=\"4\" width=\"16\" height=\"16\" rx=\"3.2\"\/>\n                <circle cx=\"9\" cy=\"9\" r=\"1.1\"\/>\n                <circle cx=\"15\" cy=\"15\" r=\"1.1\"\/>\n              <\/svg>\n            <\/div>\n            <div class=\"az-name\">Does an attack fire every time<\/div>\n          <\/th>\n          <td class=\"az-ok\" data-label=\"Ordinary Program\">\n            <span class=\"az-lead\">Yes<\/span>\n            Same input, same result, every run.\n          <\/td>\n          <td class=\"az-bad\" data-label=\"AI Agent\">\n            <span class=\"az-lead\">No<\/span>\n            Ignored once, obeyed the next time\u2014so a clean test run is not evidence the next one will be.\n          <\/td>\n        <\/tr>\n\n        <tr>\n          <th class=\"az-sig\" scope=\"row\">\n            <div class=\"az-ico\">\n              <svg viewBox=\"0 0 24 24\" aria-hidden=\"true\">\n                <path d=\"M20 5.4a4.6 4.6 0 0 1-6 6L5.9 19.5 4.4 18l8.1-8.1a4.6 4.6 0 0 1 6-6z\"\/>\n              <\/svg>\n            <\/div>\n            <div class=\"az-name\">Is there a complete fix<\/div>\n          <\/th>\n          <td class=\"az-ok\" data-label=\"Ordinary Program\">\n            <span class=\"az-lead\">Yes<\/span>\n            Parameterized queries send the command and the data separately, so the two can never merge.\n          <\/td>\n          <td class=\"az-bad\" data-label=\"AI Agent\">\n            <span class=\"az-lead\">No<\/span>\n            Plain language has no syntax you could split them by. An order and a piece of text are made of the same words.\n          <\/td>\n        <\/tr>\n\n        <tr class=\"az-key\">\n          <th class=\"az-sig\" scope=\"row\">\n            <div class=\"az-ico\">\n              <svg viewBox=\"0 0 24 24\" aria-hidden=\"true\">\n                <circle cx=\"6.2\" cy=\"6.2\" r=\"2.3\"\/>\n                <circle cx=\"6.2\" cy=\"17.8\" r=\"2.3\"\/>\n                <path d=\"M8.2 7.6L20 18\"\/>\n                <path d=\"M8.2 16.4L20 6\"\/>\n              <\/svg>\n            <\/div>\n            <div class=\"az-name\">Can the behaviour be cut out<\/div>\n          <\/th>\n          <td class=\"az-ok\" data-label=\"Ordinary Program\">\n            <span class=\"az-lead\">Yes, and nothing is lost<\/span>\n            Running data as code was never a feature. Nobody wanted it in the first place.\n          <\/td>\n          <td class=\"az-bad\" data-label=\"AI Agent\">\n            <span class=\"az-lead\">No, and this is the whole problem<\/span>\n            Following instructions written in plain words is what the agent was hired for. Switch it off for bad instructions and you switch it off for work.\n          <\/td>\n        <\/tr>\n      <\/tbody>\n    <\/table>\n  <\/div>\n\n  <div class=\"az-foot\">\n    <span class=\"az-leg\">\n      <span class=\"az-bar\" style=\"background:#00c9b8;\"><\/span>\n      Solved in ordinary software\n    <\/span>\n\n    <span class=\"az-leg\">\n      <span class=\"az-bar\" style=\"background:#e03355;\"><\/span>\n      Still open in agents\n    <\/span>\n\n    <span class=\"az-src\">\n      Prompt injection framing per\n      <a href=\"https:\/\/genai.owasp.org\/llm-top-10\/\" target=\"_blank\" rel=\"noopener noreferrer\">OWASP Top 10 for LLM Applications<\/a>\n    <\/span>\n  <\/div>\n<\/div>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"agentbaiting-the-agent-recommends-you-malware\">AgentBaiting: The Agent Recommends You Malware<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>How it works.<\/strong> A user asks the agent to find a tool for a task. The agent searches, finds a fake, reads the attacker&#8217;s README as genuine documentation, and hands the user installation instructions. No injection is required: the attacker just needs to create a fake repository that looks good enough to show it in search results. Island called this <strong>AgentBaiting<\/strong>: the goal is to mislead the agent rather than the user, which is simpler, as no AI bot adds human skepticism to the decision.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Case Study: FakeGit (July 2026). <\/strong>Island has documented roughly 7,600 fake repositories from 6,600 fake profiles on GitHub. More than 800 of them were posed as AI Skills and MCP servers, and around 1,400 more traded on AI themes. The wave built through March and peaked in April 2026, totaling more than 14 million downloads.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Each fake repository seemed like an ordinary open-source project, with plausible documentation, real code, and \u2013 on top of all that \u2013 an author profile that had a history of activity and overall looked trusted. However, in fact, it hid a two-stage payload:<\/p>\n\n\n\n<p class=\"has-cyan-bluish-gray-background-color has-background wp-block-paragraph\">1. <strong>SmartLoader.<\/strong> A small and unremarkable loader that lands on the machine and pulls down the real malware.<br>2. <strong>StealC.<\/strong> An infostealer, fetched by <strong>SmartLoader<\/strong>, that collects browser passwords, cookies, active sessions, screenshots, and digital asset wallets. Once ready, it then ships everything back to the attacker.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The user sees none of this: the tool installs and often even works exactly as advertised.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">One example: walmart-mcp. There is no official Walmart connector, but there are several third-party ones, built by enthusiasts, with near-identical names and near-identical descriptions. Asked to find the best one, Gemini and ChatGPT independently returned the same repository, and ChatGPT called it the best place to start. This repository was fake, and it won the recommendation because the attackers optimized it specifically for AI search results. All of the above is as described in the report and reflects what the models returned when the researchers ran the query. Walmart was not involved in the campaign and, on the researchers&#8217; account, its systems and services were not affected.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">An agent does not verify whether what it recommends is safe: it searches the web and works down the results. Here, Gemini and ChatGPT searched through an MCP marketplace and GitHub, opened the repositories that matched the request, and judged them on what they could see:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>A README that read as if written to answer exactly the user\u2019s request;<\/li>\n\n\n\n<li>The project turning up across public registries like LobeHub, Glama, MCP.so \u2013 where the campaign had seeded over 600 listings;<\/li>\n\n\n\n<li>The same description in every registry, which looks like several independent sources agreeing. In fact, registries just copy the README from the repository \u2013 a single source;<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">The registries were the target of this technique rather than a party to it: they publish what is submitted to them, and the campaign was built to exploit exactly that.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Genuine side projects rarely optimize for visibility this thoroughly, so they lose the search results competition.<\/p>\n\n\n<div class=\"block__preview\">\n        <a href=\"https:\/\/adex.com\/blog\/case-study-xcsset-attack\/\" class=\"block__preview_img\"><img src=\"https:\/\/adex.com\/blog\/wp-content\/uploads\/2026\/04\/Adex-xcsset-case-study.png\" srcset=\"https:\/\/adex.com\/blog\/wp-content\/uploads\/2026\/04\/Adex-xcsset-case-study.png\" sizes=\"100vw\" alt=\"Adex-xcsset-case-study\" decoding=\"async\" class=\"lazy\"><\/a>\n    <div class=\"block__preview_box\">\n        <a href=\"https:\/\/adex.com\/blog\/category\/current_risks\/\" class=\"block__preview_box-cat\">Current risks<\/a>        <h3 class=\"block__preview_box-title\" id=\"inside-the-build-first-hand-analysis-of-xcssets-attack-on-macos-developer-pipelines\"><a href=\"https:\/\/adex.com\/blog\/case-study-xcsset-attack\/\">Inside the Build: First-Hand Analysis of XCSSET&#8217;s Attack on macOS Developer Pipelines<\/a><\/h3>\n    <\/div>\n<\/div>\n<style>\n.block__preview {display: flex;align-items: center;justify-content: center; margin: 32px 0;}\n.block__preview a {text-decoration: none;}\n.block__preview_img {min-width: 360px;max-width: 360px;min-height: 188px;width: 100%;height: 100%;}\n.block__preview_img img {width: 100%;height: 100%;}\n.block__preview_box {margin-left: 40px;max-width: 360px;}\n.block__preview_box-cat {color: #00B8A7 !important;font-weight: 600;font-size: 12px;line-height: 16px;text-transform: uppercase; display: block; margin-bottom: 4px;}\n.block__preview_box-cat:hover {color: #FE645A !important; text-decoration: none !important;}\n.block__preview_box-title {font-size: 20px;font-weight: 700;line-height: 24px;color: #0B172D;}\n.block__preview_box-title a {color: #0B172D !important;}\n.block__preview_box-title a:hover {color: #FE645A !important;}\n@media screen and (max-width: 768px) {.block__preview {flex-direction: column;}.block__preview_box {max-width: 100%; margin-top: 32px;margin-left: 0px;}.block__preview_img {max-width: 100%;min-width: 100%;min-height: 100%;}}<\/style>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"tool-poisoning-the-agent-follows-an-order-hidden-in-what-it-reads\">Tool Poisoning: The Agent Follows an Order Hidden in What It Reads<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">When you activate a connector, it tells the agent what tools it has and what each one does. Those descriptions are plain text, written by whoever runs the server, and they arrive while the agent is working instead of sitting in a file you can open. The model reads them every time, but the user never sees them.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>The case: <\/strong><a href=\"https:\/\/invariantlabs.ai\/blog\/mcp-security-notification-tool-poisoning-attacks\" target=\"_blank\" rel=\"noreferrer noopener nofollow\"><strong>Invariant Labs, April 2025<\/strong><\/a><strong>.<\/strong> In the researchers&#8217; demonstration, a malicious server hid instructions inside the description of its own harmless tool \u2013 a calculator. The instructions were about a different tool: \u2018<em>when you send mail, copy this address in\u2019<\/em>. The user&#8217;s trusted email connector then sent&nbsp; every message to the attacker, even with another recipient in the field. This way, such an attack would give the attacker access to everything a user sends, and it\u2019s just a matter of time before they, for example, slip into a live payment thread with new bank details.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Note:<\/strong> At the moment, tool poisoning is described as a threat model, but there have been no real incidents publicly reported so far.<\/p>\n\n\n\n<style>\n.adexvz-13 {\n  --az-ink: #0b0f1c;\n  --az-body: #2a3347;\n  --az-faint: #8896b3;\n  --az-line: #dde3ee;\n  --az-hair: #eef1f7;\n  --az-teal: #00c9b8;\n\n  all: initial;\n  display: block !important;\n  position: relative !important;\n  width: 100% !important;\n  margin: 32px 0 !important;\n  padding: 22px 26px 18px !important;\n  color: var(--az-body) !important;\n  background: #ffffff !important;\n  border: 1px solid var(--az-line) !important;\n  border-left: 3px solid var(--az-teal) !important;\n  border-radius: 12px !important;\n  font-family: \"Inter\", -apple-system, BlinkMacSystemFont, \"Segoe UI\", Roboto, Arial, sans-serif !important;\n  text-align: left !important;\n  box-sizing: border-box !important;\n  -webkit-font-smoothing: antialiased;\n}\n\n.adexvz-13 *,\n.adexvz-13 *::before,\n.adexvz-13 *::after {\n  box-sizing: border-box !important;\n}\n\n.adexvz-13 .az-eyebrow {\n  display: flex !important;\n  align-items: center !important;\n  gap: 8px !important;\n  margin: 0 0 14px !important;\n}\n\n.adexvz-13 .az-eyebrow span {\n  color: var(--az-teal) !important;\n  font-family: inherit !important;\n  font-size: 10px !important;\n  font-weight: 700 !important;\n  line-height: 1.4 !important;\n  letter-spacing: 0.09em !important;\n  text-transform: uppercase !important;\n}\n\n.adexvz-13 .az-eyebrow svg {\n  display: block !important;\n  flex: 0 0 auto !important;\n  width: 15px !important;\n  height: 15px !important;\n  fill: none !important;\n  stroke: var(--az-teal) !important;\n  stroke-width: 1.8 !important;\n  stroke-linecap: round !important;\n  stroke-linejoin: round !important;\n}\n\n.adexvz-13 .az-q {\n  margin: 0 0 12px !important;\n  padding: 0 !important;\n  color: var(--az-body) !important;\n  border: 0 !important;\n  font-family: inherit !important;\n  font-size: 14.5px !important;\n  font-weight: 400 !important;\n  line-height: 1.62 !important;\n}\n\n.adexvz-13 .az-q:first-of-type {\n  color: var(--az-ink) !important;\n  font-size: 16px !important;\n  font-weight: 600 !important;\n  line-height: 1.55 !important;\n  letter-spacing: -0.005em !important;\n}\n\n.adexvz-13 .az-q:last-of-type {\n  margin-bottom: 16px !important;\n}\n\n.adexvz-13 .az-q b,\n.adexvz-13 .az-q strong {\n  color: var(--az-ink) !important;\n  font-weight: 700 !important;\n}\n\n.adexvz-13 .az-by {\n  display: flex !important;\n  align-items: center !important;\n  gap: 11px !important;\n  padding: 14px 0 0 !important;\n  border-top: 1px solid var(--az-hair) !important;\n}\n\n.adexvz-13 .az-av {\n  display: flex !important;\n  flex: 0 0 auto !important;\n  align-items: center !important;\n  justify-content: center !important;\n  width: 34px !important;\n  height: 34px !important;\n  color: #007a6e !important;\n  background: #d0f5ef !important;\n  border-radius: 50% !important;\n  font-family: inherit !important;\n  font-size: 12px !important;\n  font-weight: 700 !important;\n  line-height: 1 !important;\n  letter-spacing: 0.02em !important;\n}\n\n.adexvz-13 .az-who {\n  display: block !important;\n  min-width: 0 !important;\n}\n\n.adexvz-13 .az-name {\n  margin: 0 !important;\n  padding: 0 !important;\n  color: var(--az-ink) !important;\n  border: 0 !important;\n  font-family: inherit !important;\n  font-size: 13px !important;\n  font-weight: 700 !important;\n  line-height: 1.35 !important;\n}\n\n.adexvz-13 .az-role {\n  margin: 1px 0 0 !important;\n  padding: 0 !important;\n  color: var(--az-faint) !important;\n  border: 0 !important;\n  font-family: inherit !important;\n  font-size: 11.5px !important;\n  font-weight: 400 !important;\n  line-height: 1.4 !important;\n}\n\n.adexvz-13 .az-name a {\n  color: inherit !important;\n  border-bottom: 1px solid rgba(0, 201, 184, 0.55) !important;\n  font-family: inherit !important;\n  font-size: inherit !important;\n  font-weight: inherit !important;\n  text-decoration: none !important;\n}\n\n.adexvz-13 .az-name a:hover {\n  color: #007a6e !important;\n  border-bottom-color: var(--az-teal) !important;\n}\n\n@media (max-width: 700px) {\n  .adexvz-13 {\n    padding: 18px 16px 14px !important;\n  }\n\n  .adexvz-13 .az-q:first-of-type {\n    font-size: 15px !important;\n  }\n\n  .adexvz-13 .az-q {\n    font-size: 14px !important;\n  }\n}\n<\/style>\n\n<div class=\"adexvz-13\">\n  <div class=\"az-eyebrow\">\n    <svg viewBox=\"0 0 24 24\" aria-hidden=\"true\" focusable=\"false\">\n      <path d=\"M4 6.5h11\"\/>\n      <path d=\"M4 12h16\"\/>\n      <path d=\"M4 17.5h8\"\/>\n      <circle cx=\"19\" cy=\"6.5\" r=\"2.2\"\/>\n    <\/svg>\n\n    <span>How to defend against it &nbsp;&middot;&nbsp; Expert comment<\/span>\n  <\/div>\n\n  <p class=\"az-q\">If the descriptions are only ever read by the model, then a human has to check them, and before installing.<\/p>\n\n  <p class=\"az-q\">For open tools: read the SKILL.md itself, the tool descriptions and the code, including whatever executes during installation, and look at which permissions are being requested. Bear in mind that a version which is clean when you check it can turn malicious after an update.<\/p>\n\n  <p class=\"az-q\">For closed and commercial tools, study the supplier instead: terms of service, the contract, where the data goes.<\/p>\n\n  <p class=\"az-q\">And in every case, install into an isolated sandbox first. If the code and the descriptions are not available up front, that is where you get to read them once they land, and you move to a working machine only after checking.<\/p>\n\n  <div class=\"az-by\">\n    <span class=\"az-av\" aria-hidden=\"true\">SM<\/span>\n\n    <span class=\"az-who\">\n      <p class=\"az-name\">\n        <a href=\"https:\/\/www.linkedin.com\/in\/%D1%81%D0%B5%D1%80%D0%B3%D0%B5%D0%B9-%D0%BC%D0%B0%D1%80%D1%82%D1%8C%D1%8F%D0%BD%D0%BE%D0%B2-25945391\/\" target=\"_blank\" rel=\"noopener noreferrer\">Sergey Martianov<\/a>\n      <\/p>\n      <p class=\"az-role\">CPO, ADEX<\/p>\n    <\/span>\n  <\/div>\n<\/div>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"the-agent-hides-what-it-did\">The Agent Hides What It Did<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Here, the instruction tells the model to keep quiet about what it just did. Nothing is hidden from a scanner, but it\u2019s hidden from a user. In simple words, you see \u2018done, file updated\u2019 in your chat with the agent and nothing more. The part where it sent your keys off to someone else&#8217;s domain never makes it into the reply.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>The case: <\/strong><a href=\"https:\/\/arxiv.org\/abs\/2602.06547\" target=\"_blank\" rel=\"noreferrer noopener nofollow\"><strong>arXiv 2602.06547<\/strong><\/a><strong>, February to June 2026.<\/strong> Researchers took 98,380 skills from two registries and checked them by running. They confirmed 157 as malicious (0.16%), along with 632 vulnerabilities and 13 distinct techniques. After disclosure, 93.6% of what they found was taken down. The paper is named after a line they kept finding inside the malicious skills: \u2018<strong>do not mention this to the user<\/strong>.\u2019<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Formally, nothing is injected from outside: this line sits in the files of a skill you downloaded and connected yourself, and the agent reads those files because you asked it to.<\/p>\n\n\n\n<style>\n.adexvz-13 {\n  --az-ink: #0b0f1c;\n  --az-body: #2a3347;\n  --az-faint: #8896b3;\n  --az-line: #dde3ee;\n  --az-hair: #eef1f7;\n  --az-teal: #00c9b8;\n\n  all: initial;\n  display: block !important;\n  position: relative !important;\n  width: 100% !important;\n  margin: 32px 0 !important;\n  padding: 22px 26px 18px !important;\n  color: var(--az-body) !important;\n  background: #ffffff !important;\n  border: 1px solid var(--az-line) !important;\n  border-left: 3px solid var(--az-teal) !important;\n  border-radius: 12px !important;\n  font-family: \"Inter\", -apple-system, BlinkMacSystemFont, \"Segoe UI\", Roboto, Arial, sans-serif !important;\n  text-align: left !important;\n  box-sizing: border-box !important;\n  -webkit-font-smoothing: antialiased;\n}\n\n.adexvz-13 *,\n.adexvz-13 *::before,\n.adexvz-13 *::after {\n  box-sizing: border-box !important;\n}\n\n.adexvz-13 .az-eyebrow {\n  display: flex !important;\n  align-items: center !important;\n  gap: 8px !important;\n  margin: 0 0 14px !important;\n}\n\n.adexvz-13 .az-eyebrow span {\n  color: var(--az-teal) !important;\n  font-family: inherit !important;\n  font-size: 10px !important;\n  font-weight: 700 !important;\n  line-height: 1.4 !important;\n  letter-spacing: 0.09em !important;\n  text-transform: uppercase !important;\n}\n\n.adexvz-13 .az-eyebrow svg {\n  display: block !important;\n  flex: 0 0 auto !important;\n  width: 15px !important;\n  height: 15px !important;\n  fill: none !important;\n  stroke: var(--az-teal) !important;\n  stroke-width: 1.8 !important;\n  stroke-linecap: round !important;\n  stroke-linejoin: round !important;\n}\n\n.adexvz-13 .az-q {\n  margin: 0 0 12px !important;\n  padding: 0 !important;\n  color: var(--az-body) !important;\n  border: 0 !important;\n  font-family: inherit !important;\n  font-size: 14.5px !important;\n  font-weight: 400 !important;\n  line-height: 1.62 !important;\n}\n\n.adexvz-13 .az-q:first-of-type {\n  color: var(--az-ink) !important;\n  font-size: 16px !important;\n  font-weight: 600 !important;\n  line-height: 1.55 !important;\n  letter-spacing: -0.005em !important;\n}\n\n.adexvz-13 .az-q:last-of-type {\n  margin-bottom: 16px !important;\n}\n\n.adexvz-13 .az-q b,\n.adexvz-13 .az-q strong {\n  color: var(--az-ink) !important;\n  font-weight: 700 !important;\n}\n\n.adexvz-13 .az-by {\n  display: flex !important;\n  align-items: center !important;\n  gap: 11px !important;\n  padding: 14px 0 0 !important;\n  border-top: 1px solid var(--az-hair) !important;\n}\n\n.adexvz-13 .az-av {\n  display: flex !important;\n  flex: 0 0 auto !important;\n  align-items: center !important;\n  justify-content: center !important;\n  width: 34px !important;\n  height: 34px !important;\n  color: #007a6e !important;\n  background: #d0f5ef !important;\n  border-radius: 50% !important;\n  font-family: inherit !important;\n  font-size: 12px !important;\n  font-weight: 700 !important;\n  line-height: 1 !important;\n  letter-spacing: 0.02em !important;\n}\n\n.adexvz-13 .az-who {\n  display: block !important;\n  min-width: 0 !important;\n}\n\n.adexvz-13 .az-name {\n  margin: 0 !important;\n  padding: 0 !important;\n  color: var(--az-ink) !important;\n  border: 0 !important;\n  font-family: inherit !important;\n  font-size: 13px !important;\n  font-weight: 700 !important;\n  line-height: 1.35 !important;\n}\n\n.adexvz-13 .az-role {\n  margin: 1px 0 0 !important;\n  padding: 0 !important;\n  color: var(--az-faint) !important;\n  border: 0 !important;\n  font-family: inherit !important;\n  font-size: 11.5px !important;\n  font-weight: 400 !important;\n  line-height: 1.4 !important;\n}\n\n.adexvz-13 .az-name a {\n  color: inherit !important;\n  border-bottom: 1px solid rgba(0, 201, 184, 0.55) !important;\n  font-family: inherit !important;\n  font-size: inherit !important;\n  font-weight: inherit !important;\n  text-decoration: none !important;\n}\n\n.adexvz-13 .az-name a:hover {\n  color: #007a6e !important;\n  border-bottom-color: var(--az-teal) !important;\n}\n\n@media (max-width: 700px) {\n  .adexvz-13 {\n    padding: 18px 16px 14px !important;\n  }\n\n  .adexvz-13 .az-q:first-of-type {\n    font-size: 15px !important;\n  }\n\n  .adexvz-13 .az-q {\n    font-size: 14px !important;\n  }\n}\n<\/style>\n\n<div class=\"adexvz-13\">\n  <div class=\"az-eyebrow\">\n    <svg viewBox=\"0 0 24 24\" aria-hidden=\"true\" focusable=\"false\">\n      <path d=\"M4 6.5h11\"\/>\n      <path d=\"M4 12h16\"\/>\n      <path d=\"M4 17.5h8\"\/>\n      <circle cx=\"19\" cy=\"6.5\" r=\"2.2\"\/>\n    <\/svg>\n\n    <span>How to defend against it &nbsp;&middot;&nbsp; Expert comment<\/span>\n  <\/div>\n\n  <p class=\"az-q\">The agent\u2019s own account is exactly what a \u201cdo not mention this to the user\u201d line switches off. What you check is not that account, but what the application itself records.<\/p>\n\n  <p class=\"az-q\">In practice it comes down to two actions. First, expand the tool-call blocks in the conversation, because almost every client shows them collapsed. You see which tool was called, with what parameters, and what came back; if it claimed an action and there is no call, the action did not happen. Second, do not turn on \u201calways allow\u201d. With every call confirmed, you see the list of actions before they happen rather than after.<\/p>\n\n  <p class=\"az-q\">Do not count on \u201cI will look through the app and work it out\u201d, though. The log shows that a tool was called, and not what it did next: downloading and running a script from an external link looks like one harmless call. Tool descriptions, which arrive from the server at runtime, usually never reach the interface at all. And with dozens of calls in a session, nobody is going to read every one, which is what the attack counts on.<\/p>\n\n  <p class=\"az-q\">So this protects you from an agent that stays quiet about its actions, but not from a tool that hides its own. That second one is only solved at the entrance: a whitelist, a sandbox, minimal rights.<\/p>\n\n  <div class=\"az-by\">\n    <span class=\"az-av\" aria-hidden=\"true\">SM<\/span>\n\n    <span class=\"az-who\">\n      <p class=\"az-name\">\n        <a href=\"https:\/\/www.linkedin.com\/in\/%D1%81%D0%B5%D1%80%D0%B3%D0%B5%D0%B9-%D0%BC%D0%B0%D1%80%D1%82%D1%8C%D1%8F%D0%BD%D0%BE%D0%B2-25945391\/\" target=\"_blank\" rel=\"noopener noreferrer\">Sergey Martianov<\/a>\n      <\/p>\n      <p class=\"az-role\">CPO, ADEX<\/p>\n    <\/span>\n  <\/div>\n<\/div>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"rugpull-when-the-agent-becomes-the-leak\">RugPull: When The Agent Becomes the Leak<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Nobody has to break in: the agent is already inside, working under your name and with your access, so the attacker only needs whatever passes through it to go one extra place. This is the third corner of the lethal trifecta: the way out.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>The case: <\/strong><a href=\"https:\/\/www.koi.ai\/blog\/postmark-mcp-npm-malicious-backdoor-email-theft\" target=\"_blank\" rel=\"noreferrer noopener nofollow\"><strong>postmark-mcp, Koi Security<\/strong><\/a><strong>, September 2025.<\/strong> Postmark is an email-sending service. An unaffiliated publisher released a connector that <strong>looked<\/strong> official: versions up to 1.0.15 were honest, building trust along the way. <strong>This wasn&#8217;t a Postmark product \u2013 it was impersonation<\/strong>. <strong>Importantly, Postmark later confirmed publicly that the package wasn&#8217;t theirs, that they had no involvement in it, and that their actual API and service were never affected.<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Version 1.0.16 added a single line: a hidden BCC (blind carbon copy) that copied every outgoing message to the author&#8217;s own domain, invisible to everyone in the thread. From that version on, every automated email those companies sent to their users also went to the attacker. Those emails included password resets and confirmation codes, so, on Koi Security&#8217;s account, the attacker ended up holding live login links for the customers of around 300 companies. Nobody noticed, because a BCC is invisible by design: neither the sender nor the recipient sees it.<\/p>\n\n\n\n<style>\n.adexvz-13 {\n  --az-ink: #0b0f1c;\n  --az-body: #2a3347;\n  --az-faint: #8896b3;\n  --az-line: #dde3ee;\n  --az-hair: #eef1f7;\n  --az-teal: #00c9b8;\n\n  all: initial;\n  display: block !important;\n  position: relative !important;\n  width: 100% !important;\n  margin: 32px 0 !important;\n  padding: 22px 26px 18px !important;\n  color: var(--az-body) !important;\n  background: #ffffff !important;\n  border: 1px solid var(--az-line) !important;\n  border-left: 3px solid var(--az-teal) !important;\n  border-radius: 12px !important;\n  font-family: \"Inter\", -apple-system, BlinkMacSystemFont, \"Segoe UI\", Roboto, Arial, sans-serif !important;\n  text-align: left !important;\n  box-sizing: border-box !important;\n  -webkit-font-smoothing: antialiased;\n}\n\n.adexvz-13 *,\n.adexvz-13 *::before,\n.adexvz-13 *::after {\n  box-sizing: border-box !important;\n}\n\n.adexvz-13 .az-eyebrow {\n  display: flex !important;\n  align-items: center !important;\n  gap: 8px !important;\n  margin: 0 0 14px !important;\n}\n\n.adexvz-13 .az-eyebrow span {\n  color: var(--az-teal) !important;\n  font-family: inherit !important;\n  font-size: 10px !important;\n  font-weight: 700 !important;\n  line-height: 1.4 !important;\n  letter-spacing: 0.09em !important;\n  text-transform: uppercase !important;\n}\n\n.adexvz-13 .az-eyebrow svg {\n  display: block !important;\n  flex: 0 0 auto !important;\n  width: 15px !important;\n  height: 15px !important;\n  fill: none !important;\n  stroke: var(--az-teal) !important;\n  stroke-width: 1.8 !important;\n  stroke-linecap: round !important;\n  stroke-linejoin: round !important;\n}\n\n.adexvz-13 .az-q {\n  margin: 0 0 12px !important;\n  padding: 0 !important;\n  color: var(--az-body) !important;\n  border: 0 !important;\n  font-family: inherit !important;\n  font-size: 14.5px !important;\n  font-weight: 400 !important;\n  line-height: 1.62 !important;\n}\n\n.adexvz-13 .az-q:first-of-type {\n  color: var(--az-ink) !important;\n  font-size: 16px !important;\n  font-weight: 600 !important;\n  line-height: 1.55 !important;\n  letter-spacing: -0.005em !important;\n}\n\n.adexvz-13 .az-q:last-of-type {\n  margin-bottom: 16px !important;\n}\n\n.adexvz-13 .az-q b,\n.adexvz-13 .az-q strong {\n  color: var(--az-ink) !important;\n  font-weight: 700 !important;\n}\n\n.adexvz-13 .az-by {\n  display: flex !important;\n  align-items: center !important;\n  gap: 11px !important;\n  padding: 14px 0 0 !important;\n  border-top: 1px solid var(--az-hair) !important;\n}\n\n.adexvz-13 .az-av {\n  display: flex !important;\n  flex: 0 0 auto !important;\n  align-items: center !important;\n  justify-content: center !important;\n  width: 34px !important;\n  height: 34px !important;\n  color: #007a6e !important;\n  background: #d0f5ef !important;\n  border-radius: 50% !important;\n  font-family: inherit !important;\n  font-size: 12px !important;\n  font-weight: 700 !important;\n  line-height: 1 !important;\n  letter-spacing: 0.02em !important;\n}\n\n.adexvz-13 .az-who {\n  display: block !important;\n  min-width: 0 !important;\n}\n\n.adexvz-13 .az-name {\n  margin: 0 !important;\n  padding: 0 !important;\n  color: var(--az-ink) !important;\n  border: 0 !important;\n  font-family: inherit !important;\n  font-size: 13px !important;\n  font-weight: 700 !important;\n  line-height: 1.35 !important;\n}\n\n.adexvz-13 .az-role {\n  margin: 1px 0 0 !important;\n  padding: 0 !important;\n  color: var(--az-faint) !important;\n  border: 0 !important;\n  font-family: inherit !important;\n  font-size: 11.5px !important;\n  font-weight: 400 !important;\n  line-height: 1.4 !important;\n}\n\n.adexvz-13 .az-name a {\n  color: inherit !important;\n  border-bottom: 1px solid rgba(0, 201, 184, 0.55) !important;\n  font-family: inherit !important;\n  font-size: inherit !important;\n  font-weight: inherit !important;\n  text-decoration: none !important;\n}\n\n.adexvz-13 .az-name a:hover {\n  color: #007a6e !important;\n  border-bottom-color: var(--az-teal) !important;\n}\n\n@media (max-width: 700px) {\n  .adexvz-13 {\n    padding: 18px 16px 14px !important;\n  }\n\n  .adexvz-13 .az-q:first-of-type {\n    font-size: 15px !important;\n  }\n\n  .adexvz-13 .az-q {\n    font-size: 14px !important;\n  }\n}\n<\/style>\n\n<div class=\"adexvz-13\">\n  <div class=\"az-eyebrow\">\n    <svg viewBox=\"0 0 24 24\" aria-hidden=\"true\" focusable=\"false\">\n      <path d=\"M4 6.5h11\"\/>\n      <path d=\"M4 12h16\"\/>\n      <path d=\"M4 17.5h8\"\/>\n      <circle cx=\"19\" cy=\"6.5\" r=\"2.2\"\/>\n    <\/svg>\n\n    <span>How to defend against it &nbsp;&middot;&nbsp; Expert comment<\/span>\n  <\/div>\n\n  <p class=\"az-q\">You cannot shut the channel completely: a tool that goes out to the network needs the network to do its job. What you take away is not the channel, but whatever can be carried out through it.<\/p>\n\n  <p class=\"az-q\">In practice, access no wider than the task. The project\u2019s working folder, not your whole home directory. A separate browser profile, not the main one holding every session. Test keys instead of production ones, read-only and scoped to one project instead of a universal token. And do not mix private data and untrusted content in one session: going through someone else\u2019s repository and working with your mail are two different sessions.<\/p>\n\n  <p class=\"az-q\">Plus confirmation on everything that leaves: an email, a commit, a write to an external service. This is exactly where \u201calways allow\u201d costs the most.<\/p>\n\n  <p class=\"az-q\">Where you can, run the agent in a container or on a separate machine with no SSH keys and no cloud credentials on it, and allow outgoing connections only to the domains it needs.<\/p>\n\n  <div class=\"az-by\">\n    <span class=\"az-av\" aria-hidden=\"true\">SM<\/span>\n\n    <span class=\"az-who\">\n      <p class=\"az-name\">\n        <a href=\"https:\/\/www.linkedin.com\/in\/%D1%81%D0%B5%D1%80%D0%B3%D0%B5%D0%B9-%D0%BC%D0%B0%D1%80%D1%82%D1%8C%D1%8F%D0%BD%D0%BE%D0%B2-25945391\/\" target=\"_blank\" rel=\"noopener noreferrer\">Sergey Martianov<\/a>\n      <\/p>\n      <p class=\"az-role\">CPO, ADEX<\/p>\n    <\/span>\n  <\/div>\n<\/div>\n\n\n<div class=\"block__bord\"><div class=\"block__bord_desc\"><p><strong>Note: Those honest versions were the whole point. Your approval covers the version you looked at; nothing asks you again when an update arrives, and auto-update turns one confirmation into a standing confirmation for everything the author ships next. That trick has a name: rug pull.<\/strong><\/p>\n<\/div><\/div>\n<style>\n.block__bord { margin: 32px 0; padding: 1.25em 2.375em;\tborder-radius: 24px; background: rgba(0, 220, 200, 0.20); }\n.block__bord_desc {font-size: 16px !important;font-weight: 400 !important;color: #606060 !important;}\n<\/style>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"the-swap-can-happen-outside-the-package\">The Swap Can Happen Outside the Package<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Pinning versions and reading diffs both assume that what changes is the package, but sometimes it happens outside.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Case 1: <\/strong><a href=\"https:\/\/research.checkpoint.com\/2025\/cursor-vulnerability-mcpoison\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\"><strong>MCPoison in Cursor, CVE-2025-54136<\/strong><\/a><strong> (Check Point, August 2025)<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Cursor is a code editor with an AI assistant built in, and it takes its settings from a file inside the project so the whole team works the same way.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Once you approve that file, the editor did not re-check it in the affected versions. An attacker with commit rights to a shared repo could plant a harmless config, wait for the approval, then change the command inside, and get code running every time anyone opened the project, with nothing asked. Fixed in Cursor 1.3, where any edit at all, down to an added space, has to be approved again. Researchers found this and reported it, so no exploitation in the wild was reported.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Case 2: <\/strong><a href=\"https:\/\/www.air.security\/blog-posts\/the-story-of-skills\" target=\"_blank\" rel=\"noreferrer noopener nofollow\"><strong>the skill that reached 26,000 agents<\/strong><\/a><strong> (AIR, June 2026).<\/strong> Researchers sent a pull request for a skill called brand-landingpage to a popular marketplace with around 36,000 stars. It was merged, and from that moment the skill wore the repository&#8217;s reputation. Instagram ads aimed at marketers and designers did the rest, putting it on roughly 26,000 real users&#8217; agents.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The swap happened outside the package. The domain the skill pointed at served genuine documentation at first, and once the installs had piled up, that page turned into instructions telling the agent to download and run a script. The scanners the researchers tested missed it, for a simple reason: they read the package that was submitted, and the other end of a link can change at any time.<\/p>\n\n\n\n<style>\n.adexvz-13 {\n  --az-ink: #0b0f1c;\n  --az-body: #2a3347;\n  --az-faint: #8896b3;\n  --az-line: #dde3ee;\n  --az-hair: #eef1f7;\n  --az-teal: #00c9b8;\n\n  all: initial;\n  display: block !important;\n  position: relative !important;\n  width: 100% !important;\n  margin: 32px 0 !important;\n  padding: 22px 26px 18px !important;\n  color: var(--az-body) !important;\n  background: #ffffff !important;\n  border: 1px solid var(--az-line) !important;\n  border-left: 3px solid var(--az-teal) !important;\n  border-radius: 12px !important;\n  font-family: \"Inter\", -apple-system, BlinkMacSystemFont, \"Segoe UI\", Roboto, Arial, sans-serif !important;\n  text-align: left !important;\n  box-sizing: border-box !important;\n  -webkit-font-smoothing: antialiased;\n}\n\n.adexvz-13 *,\n.adexvz-13 *::before,\n.adexvz-13 *::after {\n  box-sizing: border-box !important;\n}\n\n.adexvz-13 .az-eyebrow {\n  display: flex !important;\n  align-items: center !important;\n  gap: 8px !important;\n  margin: 0 0 14px !important;\n}\n\n.adexvz-13 .az-eyebrow span {\n  color: var(--az-teal) !important;\n  font-family: inherit !important;\n  font-size: 10px !important;\n  font-weight: 700 !important;\n  line-height: 1.4 !important;\n  letter-spacing: 0.09em !important;\n  text-transform: uppercase !important;\n}\n\n.adexvz-13 .az-eyebrow svg {\n  display: block !important;\n  flex: 0 0 auto !important;\n  width: 15px !important;\n  height: 15px !important;\n  fill: none !important;\n  stroke: var(--az-teal) !important;\n  stroke-width: 1.8 !important;\n  stroke-linecap: round !important;\n  stroke-linejoin: round !important;\n}\n\n.adexvz-13 .az-q {\n  margin: 0 0 12px !important;\n  padding: 0 !important;\n  color: var(--az-body) !important;\n  border: 0 !important;\n  font-family: inherit !important;\n  font-size: 14.5px !important;\n  font-weight: 400 !important;\n  line-height: 1.62 !important;\n}\n\n.adexvz-13 .az-q:first-of-type {\n  color: var(--az-ink) !important;\n  font-size: 16px !important;\n  font-weight: 600 !important;\n  line-height: 1.55 !important;\n  letter-spacing: -0.005em !important;\n}\n\n.adexvz-13 .az-q:last-of-type {\n  margin-bottom: 16px !important;\n}\n\n.adexvz-13 .az-q b,\n.adexvz-13 .az-q strong {\n  color: var(--az-ink) !important;\n  font-weight: 700 !important;\n}\n\n.adexvz-13 .az-by {\n  display: flex !important;\n  align-items: center !important;\n  gap: 11px !important;\n  padding: 14px 0 0 !important;\n  border-top: 1px solid var(--az-hair) !important;\n}\n\n.adexvz-13 .az-av {\n  display: flex !important;\n  flex: 0 0 auto !important;\n  align-items: center !important;\n  justify-content: center !important;\n  width: 34px !important;\n  height: 34px !important;\n  color: #007a6e !important;\n  background: #d0f5ef !important;\n  border-radius: 50% !important;\n  font-family: inherit !important;\n  font-size: 12px !important;\n  font-weight: 700 !important;\n  line-height: 1 !important;\n  letter-spacing: 0.02em !important;\n}\n\n.adexvz-13 .az-who {\n  display: block !important;\n  min-width: 0 !important;\n}\n\n.adexvz-13 .az-name {\n  margin: 0 !important;\n  padding: 0 !important;\n  color: var(--az-ink) !important;\n  border: 0 !important;\n  font-family: inherit !important;\n  font-size: 13px !important;\n  font-weight: 700 !important;\n  line-height: 1.35 !important;\n}\n\n.adexvz-13 .az-role {\n  margin: 1px 0 0 !important;\n  padding: 0 !important;\n  color: var(--az-faint) !important;\n  border: 0 !important;\n  font-family: inherit !important;\n  font-size: 11.5px !important;\n  font-weight: 400 !important;\n  line-height: 1.4 !important;\n}\n\n.adexvz-13 .az-name a {\n  color: inherit !important;\n  border-bottom: 1px solid rgba(0, 201, 184, 0.55) !important;\n  font-family: inherit !important;\n  font-size: inherit !important;\n  font-weight: inherit !important;\n  text-decoration: none !important;\n}\n\n.adexvz-13 .az-name a:hover {\n  color: #007a6e !important;\n  border-bottom-color: var(--az-teal) !important;\n}\n\n@media (max-width: 700px) {\n  .adexvz-13 {\n    padding: 18px 16px 14px !important;\n  }\n\n  .adexvz-13 .az-q:first-of-type {\n    font-size: 15px !important;\n  }\n\n  .adexvz-13 .az-q {\n    font-size: 14px !important;\n  }\n}\n<\/style>\n\n<div class=\"adexvz-13\">\n  <div class=\"az-eyebrow\">\n    <svg viewBox=\"0 0 24 24\" aria-hidden=\"true\" focusable=\"false\">\n      <path d=\"M4 6.5h11\"\/>\n      <path d=\"M4 12h16\"\/>\n      <path d=\"M4 17.5h8\"\/>\n      <circle cx=\"19\" cy=\"6.5\" r=\"2.2\"\/>\n    <\/svg>\n\n    <span>How to defend against it &nbsp;&middot;&nbsp; Expert comment<\/span>\n  <\/div>\n\n  <p class=\"az-q\">Start from the assumption that approval attaches to a version, not to a tool. Versions of postmark-mcp up to 1.0.15 were honest, and the next one added a hidden BCC. Which makes auto-update a consent you handed over in advance, for everything that arrives later.<\/p>\n\n  <p class=\"az-q\">In practice: turn auto-update off for anything with broad permissions, and update deliberately, looking at what changed. Do not install the newest release on the day it ships without a reason. Treat it as a warning sign if a tool asks for more rights after an update, or starts reaching places it never reached before.<\/p>\n\n  <p class=\"az-q\">Updates to the client itself deserve separate attention. MCPoison in Cursor was fixed precisely by making any config change require fresh approval, which means older clients have no such protection.<\/p>\n\n  <p class=\"az-q\">Honestly, though, this does not close all the way. In the AIR case what was swapped was the content of a page behind an external link, and not the package: the skill\u2019s version never changed at all, so there was nothing to update. Update control is only one part. The rest comes from the tool having few rights to begin with, and little of value around it.<\/p>\n\n  <div class=\"az-by\">\n    <span class=\"az-av\" aria-hidden=\"true\">SM<\/span>\n\n    <span class=\"az-who\">\n      <p class=\"az-name\">\n        <a href=\"https:\/\/www.linkedin.com\/in\/%D1%81%D0%B5%D1%80%D0%B3%D0%B5%D0%B9-%D0%BC%D0%B0%D1%80%D1%82%D1%8C%D1%8F%D0%BD%D0%BE%D0%B2-25945391\/\" target=\"_blank\" rel=\"noopener noreferrer\">Sergey Martianov<\/a>\n      <\/p>\n      <p class=\"az-role\">CPO, ADEX<\/p>\n    <\/span>\n  <\/div>\n<\/div>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"opening-someones-project-can-run-their-code\">Opening Someone&#8217;s Project Can Run Their Code<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Developers copy other people&#8217;s projects onto their machines dozens of times just to read them. It used to be harmless, because text sitting on your disk does nothing on its own.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Editors with an AI assistant changed that: they take settings from a file inside the project, so everyone on a team works the same way, and the person who published the project is the one who wrote that file. It can tell the assistant to run a command as soon as the project opens.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/research.checkpoint.com\/2026\/rce-and-api-token-exfiltration-through-claude-code-project-files-cve-2025-59536\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\"><strong>Check Point, February 2026<\/strong><\/a><strong>.<\/strong> Claude Code reads its settings from a file in the repository, and anyone with access to the repository can edit it. There was a guard, though: when you open an unfamiliar folder, a window asks whether you trust this project. Check Point showed that the command in the settings ran before anyone finished reading the question. The three findings below were reported by Check Point and, per the vendor advisories, have all been fixed in the versions and on the dates noted.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Three findings, all fixed since:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Opening a folder in a new location skipped the permission step altogether (fixed September 2025);<\/li>\n\n\n\n<li>Opening an untrusted folder could run any command on your machine, from deleting files to downloading a program to sending your data somewhere (CVE-2025-59536, fixed October 2025);<\/li>\n\n\n\n<li>The settings could point the assistant at the attacker&#8217;s server instead of the real one, and it handed over the API key on arrival, the key you are billed for (CVE-2026-21852, fixed January 2026).<\/li>\n<\/ul>\n\n\n\n<style>\n.adexvz-13 {\n  --az-ink: #0b0f1c;\n  --az-body: #2a3347;\n  --az-faint: #8896b3;\n  --az-line: #dde3ee;\n  --az-hair: #eef1f7;\n  --az-teal: #00c9b8;\n\n  all: initial;\n  display: block !important;\n  position: relative !important;\n  width: 100% !important;\n  margin: 32px 0 !important;\n  padding: 22px 26px 18px !important;\n  color: var(--az-body) !important;\n  background: #ffffff !important;\n  border: 1px solid var(--az-line) !important;\n  border-left: 3px solid var(--az-teal) !important;\n  border-radius: 12px !important;\n  font-family: \"Inter\", -apple-system, BlinkMacSystemFont, \"Segoe UI\", Roboto, Arial, sans-serif !important;\n  text-align: left !important;\n  box-sizing: border-box !important;\n  -webkit-font-smoothing: antialiased;\n}\n\n.adexvz-13 *,\n.adexvz-13 *::before,\n.adexvz-13 *::after {\n  box-sizing: border-box !important;\n}\n\n.adexvz-13 .az-eyebrow {\n  display: flex !important;\n  align-items: center !important;\n  gap: 8px !important;\n  margin: 0 0 14px !important;\n}\n\n.adexvz-13 .az-eyebrow span {\n  color: var(--az-teal) !important;\n  font-family: inherit !important;\n  font-size: 10px !important;\n  font-weight: 700 !important;\n  line-height: 1.4 !important;\n  letter-spacing: 0.09em !important;\n  text-transform: uppercase !important;\n}\n\n.adexvz-13 .az-eyebrow svg {\n  display: block !important;\n  flex: 0 0 auto !important;\n  width: 15px !important;\n  height: 15px !important;\n  fill: none !important;\n  stroke: var(--az-teal) !important;\n  stroke-width: 1.8 !important;\n  stroke-linecap: round !important;\n  stroke-linejoin: round !important;\n}\n\n.adexvz-13 .az-q {\n  margin: 0 0 12px !important;\n  padding: 0 !important;\n  color: var(--az-body) !important;\n  border: 0 !important;\n  font-family: inherit !important;\n  font-size: 14.5px !important;\n  font-weight: 400 !important;\n  line-height: 1.62 !important;\n}\n\n.adexvz-13 .az-q:first-of-type {\n  color: var(--az-ink) !important;\n  font-size: 16px !important;\n  font-weight: 600 !important;\n  line-height: 1.55 !important;\n  letter-spacing: -0.005em !important;\n}\n\n.adexvz-13 .az-q:last-of-type {\n  margin-bottom: 16px !important;\n}\n\n.adexvz-13 .az-by {\n  display: flex !important;\n  align-items: center !important;\n  gap: 11px !important;\n  padding: 14px 0 0 !important;\n  border-top: 1px solid var(--az-hair) !important;\n}\n\n.adexvz-13 .az-av {\n  display: flex !important;\n  flex: 0 0 auto !important;\n  align-items: center !important;\n  justify-content: center !important;\n  width: 34px !important;\n  height: 34px !important;\n  color: #007a6e !important;\n  background: #d0f5ef !important;\n  border-radius: 50% !important;\n  font-family: inherit !important;\n  font-size: 12px !important;\n  font-weight: 700 !important;\n  line-height: 1 !important;\n  letter-spacing: 0.02em !important;\n}\n\n.adexvz-13 .az-who {\n  display: block !important;\n  min-width: 0 !important;\n}\n\n.adexvz-13 .az-name {\n  margin: 0 !important;\n  padding: 0 !important;\n  color: var(--az-ink) !important;\n  border: 0 !important;\n  font-family: inherit !important;\n  font-size: 13px !important;\n  font-weight: 700 !important;\n  line-height: 1.35 !important;\n}\n\n.adexvz-13 .az-role {\n  margin: 1px 0 0 !important;\n  padding: 0 !important;\n  color: var(--az-faint) !important;\n  border: 0 !important;\n  font-family: inherit !important;\n  font-size: 11.5px !important;\n  font-weight: 400 !important;\n  line-height: 1.4 !important;\n}\n\n.adexvz-13 .az-name a {\n  color: inherit !important;\n  border-bottom: 1px solid rgba(0, 201, 184, 0.55) !important;\n  font-family: inherit !important;\n  font-size: inherit !important;\n  font-weight: inherit !important;\n  text-decoration: none !important;\n}\n\n.adexvz-13 .az-name a:hover {\n  color: #007a6e !important;\n  border-bottom-color: var(--az-teal) !important;\n}\n\n@media (max-width: 700px) {\n  .adexvz-13 {\n    padding: 18px 16px 14px !important;\n  }\n\n  .adexvz-13 .az-q:first-of-type {\n    font-size: 15px !important;\n  }\n\n  .adexvz-13 .az-q {\n    font-size: 14px !important;\n  }\n}\n<\/style>\n\n<div class=\"adexvz-13\">\n  <div class=\"az-eyebrow\">\n    <svg viewBox=\"0 0 24 24\" aria-hidden=\"true\" focusable=\"false\">\n      <path d=\"M4 6.5h11\"><\/path>\n      <path d=\"M4 12h16\"><\/path>\n      <path d=\"M4 17.5h8\"><\/path>\n      <circle cx=\"19\" cy=\"6.5\" r=\"2.2\"><\/circle>\n    <\/svg>\n\n    <span>How to defend against it &nbsp;\u00b7&nbsp; Expert comment<\/span>\n  <\/div>\n\n  <p class=\"az-q\">Copying a project onto your machine and opening it used to be a neutral act. Now the editor reads its configuration out of the repository itself, and whoever has commit rights controls that configuration.<\/p>\n\n  <p class=\"az-q\">The first line of defense is already built in. Modern IDEs ask whether you trust an unfamiliar project, and in restricted mode they will not run its settings or its tasks. So do not click \u201cI trust this\u201d on reflex, and stay in restricted mode while you are only reading someone else\u2019s code.<\/p>\n\n  <p class=\"az-q\">Do not lean on that alone, though. Some of the holes that were found bypassed that dialog exactly, firing before the user could read it, which is why the editor has to be kept updated.<\/p>\n\n  <p class=\"az-q\">Where you can, open unfamiliar projects in a container or on a separate machine that holds no keys and no tokens. And remember that a repository\u2019s popularity guarantees nothing: a harmful config can arrive there through an accepted pull request.<\/p>\n\n  <div class=\"az-by\">\n    <span class=\"az-av\" aria-hidden=\"true\">SM<\/span>\n\n    <span class=\"az-who\">\n      <p class=\"az-name\">\n        <a href=\"https:\/\/www.linkedin.com\/in\/%D1%81%D0%B5%D1%80%D0%B3%D0%B5%D0%B9-%D0%BC%D0%B0%D1%80%D1%82%D1%8C%D1%8F%D0%BD%D0%BE%D0%B2-25945391\/\" target=\"_blank\" rel=\"noopener noreferrer\">Sergey Martianov<\/a>\n      <\/p>\n      <p class=\"az-role\">CPO, ADEX<\/p>\n    <\/span>\n  <\/div>\n<\/div>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"clickfix-when-a-user-installs-malware-deliberately\">ClickFix: When A User Installs Malware Deliberately<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The dullest but the most effective technique we\u2019ll mention here: there is no injection, just an instruction written for a user. A README or a SKILL.md carries a \u2018Prerequisites\u2019 section, the part of any documentation that tells you what to set up first, and it asks you to paste a command into your terminal or grab a helper tool.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">You copy and paste, then press Enter, and so install the malware with your own hands. This technique is called <strong>ClickFix<\/strong>.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>The case: <\/strong><a href=\"https:\/\/www.antiy.net\/p\/clawhavoc-analysis-of-large-scale-poisoning-campaign-targeting-the-openclaw-skill-market-for-ai-agents\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\"><strong>ClawHavoc<\/strong><\/a><strong> (Koi Security and Antiy CERT, January to February 2026).<\/strong> ClawHub is a public skill registry for the OpenClaw agent, and anyone with a GitHub account older than one week could publish there. From January 27, attackers began bulk-uploading skills dressed as Blockchain and office utilities, peaking on the 31st, and Koi named the campaign on February 1.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The two organizations measured different things, so their numbers shouldn&#8217;t be added together or read as two estimates of the same total. Koi&#8217;s snapshot audit found 341 malicious skills among the 2,857 then live on ClawHub, 335 of them from a single campaign. Antiy CERT&#8217;s cumulative count, tracked over time, puts it at 1,184 malicious skills tied to just 12 accounts \u2013 one account alone uploaded 677.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">What they took: Blockchain wallets, browser passwords, API keys, the macOS Keychain (every saved password at once), SSH keys, and Telegram sessions.&nbsp;<\/p>\n\n\n\n<style>\n.adexvz-13 {\n  --az-ink: #0b0f1c;\n  --az-body: #2a3347;\n  --az-faint: #8896b3;\n  --az-line: #dde3ee;\n  --az-hair: #eef1f7;\n  --az-teal: #00c9b8;\n\n  all: initial;\n  display: block !important;\n  position: relative !important;\n  width: 100% !important;\n  margin: 32px 0 !important;\n  padding: 22px 26px 18px !important;\n  color: var(--az-body) !important;\n  background: #ffffff !important;\n  border: 1px solid var(--az-line) !important;\n  border-left: 3px solid var(--az-teal) !important;\n  border-radius: 12px !important;\n  font-family: \"Inter\", -apple-system, BlinkMacSystemFont, \"Segoe UI\", Roboto, Arial, sans-serif !important;\n  text-align: left !important;\n  box-sizing: border-box !important;\n  -webkit-font-smoothing: antialiased;\n}\n\n.adexvz-13 *,\n.adexvz-13 *::before,\n.adexvz-13 *::after {\n  box-sizing: border-box !important;\n}\n\n.adexvz-13 .az-eyebrow {\n  display: flex !important;\n  align-items: center !important;\n  gap: 8px !important;\n  margin: 0 0 14px !important;\n}\n\n.adexvz-13 .az-eyebrow span {\n  color: var(--az-teal) !important;\n  font-family: inherit !important;\n  font-size: 10px !important;\n  font-weight: 700 !important;\n  line-height: 1.4 !important;\n  letter-spacing: 0.09em !important;\n  text-transform: uppercase !important;\n}\n\n.adexvz-13 .az-eyebrow svg {\n  display: block !important;\n  flex: 0 0 auto !important;\n  width: 15px !important;\n  height: 15px !important;\n  fill: none !important;\n  stroke: var(--az-teal) !important;\n  stroke-width: 1.8 !important;\n  stroke-linecap: round !important;\n  stroke-linejoin: round !important;\n}\n\n.adexvz-13 .az-q {\n  margin: 0 0 12px !important;\n  padding: 0 !important;\n  color: var(--az-body) !important;\n  border: 0 !important;\n  font-family: inherit !important;\n  font-size: 14.5px !important;\n  font-weight: 400 !important;\n  line-height: 1.62 !important;\n}\n\n.adexvz-13 .az-q:first-of-type {\n  color: var(--az-ink) !important;\n  font-size: 16px !important;\n  font-weight: 600 !important;\n  line-height: 1.55 !important;\n  letter-spacing: -0.005em !important;\n}\n\n.adexvz-13 .az-q:last-of-type {\n  margin-bottom: 16px !important;\n}\n\n.adexvz-13 .az-q b,\n.adexvz-13 .az-q strong {\n  color: var(--az-ink) !important;\n  font-weight: 700 !important;\n}\n\n.adexvz-13 .az-by {\n  display: flex !important;\n  align-items: center !important;\n  gap: 11px !important;\n  padding: 14px 0 0 !important;\n  border-top: 1px solid var(--az-hair) !important;\n}\n\n.adexvz-13 .az-av {\n  display: flex !important;\n  flex: 0 0 auto !important;\n  align-items: center !important;\n  justify-content: center !important;\n  width: 34px !important;\n  height: 34px !important;\n  color: #007a6e !important;\n  background: #d0f5ef !important;\n  border-radius: 50% !important;\n  font-family: inherit !important;\n  font-size: 12px !important;\n  font-weight: 700 !important;\n  line-height: 1 !important;\n  letter-spacing: 0.02em !important;\n}\n\n.adexvz-13 .az-who {\n  display: block !important;\n  min-width: 0 !important;\n}\n\n.adexvz-13 .az-name {\n  margin: 0 !important;\n  padding: 0 !important;\n  color: var(--az-ink) !important;\n  border: 0 !important;\n  font-family: inherit !important;\n  font-size: 13px !important;\n  font-weight: 700 !important;\n  line-height: 1.35 !important;\n}\n\n.adexvz-13 .az-role {\n  margin: 1px 0 0 !important;\n  padding: 0 !important;\n  color: var(--az-faint) !important;\n  border: 0 !important;\n  font-family: inherit !important;\n  font-size: 11.5px !important;\n  font-weight: 400 !important;\n  line-height: 1.4 !important;\n}\n\n.adexvz-13 .az-name a {\n  color: inherit !important;\n  border-bottom: 1px solid rgba(0, 201, 184, 0.55) !important;\n  font-family: inherit !important;\n  font-size: inherit !important;\n  font-weight: inherit !important;\n  text-decoration: none !important;\n}\n\n.adexvz-13 .az-name a:hover {\n  color: #007a6e !important;\n  border-bottom-color: var(--az-teal) !important;\n}\n\n@media (max-width: 700px) {\n  .adexvz-13 {\n    padding: 18px 16px 14px !important;\n  }\n\n  .adexvz-13 .az-q:first-of-type {\n    font-size: 15px !important;\n  }\n\n  .adexvz-13 .az-q {\n    font-size: 14px !important;\n  }\n}\n<\/style>\n\n<div class=\"adexvz-13\">\n  <div class=\"az-eyebrow\">\n    <svg viewBox=\"0 0 24 24\" aria-hidden=\"true\" focusable=\"false\">\n      <path d=\"M4 6.5h11\"><\/path>\n      <path d=\"M4 12h16\"><\/path>\n      <path d=\"M4 17.5h8\"><\/path>\n      <circle cx=\"19\" cy=\"6.5\" r=\"2.2\"><\/circle>\n    <\/svg>\n\n    <span>How to defend against it &nbsp;\u00b7&nbsp; Expert comment<\/span>\n  <\/div>\n\n  <p class=\"az-q\">Technical controls are almost powerless here, and it is down to how the attack is built. There is no malicious code in the repository, so a scanner has nothing to find. What sits there is text addressed to a human.<\/p>\n\n  <p class=\"az-q\">The command is run by the user, voluntarily and by hand, which makes it a normal action as far as the system is concerned.<\/p>\n\n  <p class=\"az-q\">Something does work after the fact: antivirus or EDR may react to whatever was downloaded and launched. But that is catching the consequences rather than the trick itself, and it gets bypassed by routine means.<\/p>\n\n  <div class=\"az-by\">\n    <span class=\"az-av\" aria-hidden=\"true\">SM<\/span>\n\n    <span class=\"az-who\">\n      <p class=\"az-name\">\n        <a href=\"https:\/\/www.linkedin.com\/in\/%D1%81%D0%B5%D1%80%D0%B3%D0%B5%D0%B9-%D0%BC%D0%B0%D1%80%D1%82%D1%8C%D1%8F%D0%BD%D0%BE%D0%B2-25945391\/\" target=\"_blank\" rel=\"noopener noreferrer\">Sergey Martianov<\/a>\n      <\/p>\n      <p class=\"az-role\">CPO, ADEX<\/p>\n    <\/span>\n  <\/div>\n<\/div>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"the-agent-as-the-weapon\">The Agent as the Weapon<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The other direction: the agent is the one doing the attacking. Penetration testing tools are standard security software for probing defenses, finding holes, guessing passwords, checking where somebody could get through.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Connect them to an assistant as MCP servers, the same way you would connect anything else, and the assistant starts running them itself.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>The case: <\/strong><a href=\"https:\/\/www.anthropic.com\/news\/disrupting-AI-espionage\" target=\"_blank\" rel=\"noreferrer noopener nofollow\"><strong>GTG-1002<\/strong><\/a><strong>, reported by Anthropic, November 2025.<\/strong> Anthropic published an account of a campaign it calls the first documented case of AI-orchestrated cyber espionage. The attribution \u2013 an East Asian state-sponsored group \u2013 is Anthropic&#8217;s own assessment; it hasn&#8217;t been independently confirmed in public threat-intelligence repositories, so this is a vendor&#8217;s account of the incident, not a verified industry finding. In plain terms: normally a human operator decides the order of an attack, running a scanner, reading the result, picking the next step.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Here, the model took that role. The attackers wired open-source pentest tools into Claude Code as MCP servers, set the objective, and the model worked out what to run next and what to do with each result. Anthropic puts 80 to 90 percent of tactical operations at no human involvement, leaving the operator to set goals and choose the major forks.<\/p>\n\n\n\n<style>\n.adexvz-13 {\n  --az-ink: #0b0f1c;\n  --az-body: #2a3347;\n  --az-faint: #8896b3;\n  --az-line: #dde3ee;\n  --az-hair: #eef1f7;\n  --az-teal: #00c9b8;\n\n  all: initial;\n  display: block !important;\n  position: relative !important;\n  width: 100% !important;\n  margin: 32px 0 !important;\n  padding: 22px 26px 18px !important;\n  color: var(--az-body) !important;\n  background: #ffffff !important;\n  border: 1px solid var(--az-line) !important;\n  border-left: 3px solid var(--az-teal) !important;\n  border-radius: 12px !important;\n  font-family: \"Inter\", -apple-system, BlinkMacSystemFont, \"Segoe UI\", Roboto, Arial, sans-serif !important;\n  text-align: left !important;\n  box-sizing: border-box !important;\n  -webkit-font-smoothing: antialiased;\n}\n\n.adexvz-13 *,\n.adexvz-13 *::before,\n.adexvz-13 *::after {\n  box-sizing: border-box !important;\n}\n\n.adexvz-13 .az-eyebrow {\n  display: flex !important;\n  align-items: center !important;\n  gap: 8px !important;\n  margin: 0 0 14px !important;\n}\n\n.adexvz-13 .az-eyebrow span {\n  color: var(--az-teal) !important;\n  font-family: inherit !important;\n  font-size: 10px !important;\n  font-weight: 700 !important;\n  line-height: 1.4 !important;\n  letter-spacing: 0.09em !important;\n  text-transform: uppercase !important;\n}\n\n.adexvz-13 .az-eyebrow svg {\n  display: block !important;\n  flex: 0 0 auto !important;\n  width: 15px !important;\n  height: 15px !important;\n  fill: none !important;\n  stroke: var(--az-teal) !important;\n  stroke-width: 1.8 !important;\n  stroke-linecap: round !important;\n  stroke-linejoin: round !important;\n}\n\n.adexvz-13 .az-q {\n  margin: 0 0 12px !important;\n  padding: 0 !important;\n  color: var(--az-body) !important;\n  border: 0 !important;\n  font-family: inherit !important;\n  font-size: 14.5px !important;\n  font-weight: 400 !important;\n  line-height: 1.62 !important;\n}\n\n.adexvz-13 .az-q:first-of-type {\n  color: var(--az-ink) !important;\n  font-size: 16px !important;\n  font-weight: 600 !important;\n  line-height: 1.55 !important;\n  letter-spacing: -0.005em !important;\n}\n\n.adexvz-13 .az-q:last-of-type {\n  margin-bottom: 16px !important;\n}\n\n.adexvz-13 .az-q b,\n.adexvz-13 .az-q strong {\n  color: var(--az-ink) !important;\n  font-weight: 700 !important;\n}\n\n.adexvz-13 .az-by {\n  display: flex !important;\n  align-items: center !important;\n  gap: 11px !important;\n  padding: 14px 0 0 !important;\n  border-top: 1px solid var(--az-hair) !important;\n}\n\n.adexvz-13 .az-av {\n  display: flex !important;\n  flex: 0 0 auto !important;\n  align-items: center !important;\n  justify-content: center !important;\n  width: 34px !important;\n  height: 34px !important;\n  color: #007a6e !important;\n  background: #d0f5ef !important;\n  border-radius: 50% !important;\n  font-family: inherit !important;\n  font-size: 12px !important;\n  font-weight: 700 !important;\n  line-height: 1 !important;\n  letter-spacing: 0.02em !important;\n}\n\n.adexvz-13 .az-who {\n  display: block !important;\n  min-width: 0 !important;\n}\n\n.adexvz-13 .az-name {\n  margin: 0 !important;\n  padding: 0 !important;\n  color: var(--az-ink) !important;\n  border: 0 !important;\n  font-family: inherit !important;\n  font-size: 13px !important;\n  font-weight: 700 !important;\n  line-height: 1.35 !important;\n}\n\n.adexvz-13 .az-role {\n  margin: 1px 0 0 !important;\n  padding: 0 !important;\n  color: var(--az-faint) !important;\n  border: 0 !important;\n  font-family: inherit !important;\n  font-size: 11.5px !important;\n  font-weight: 400 !important;\n  line-height: 1.4 !important;\n}\n\n.adexvz-13 .az-name a {\n  color: inherit !important;\n  border-bottom: 1px solid rgba(0, 201, 184, 0.55) !important;\n  font-family: inherit !important;\n  font-size: inherit !important;\n  font-weight: inherit !important;\n  text-decoration: none !important;\n}\n\n.adexvz-13 .az-name a:hover {\n  color: #007a6e !important;\n  border-bottom-color: var(--az-teal) !important;\n}\n\n@media (max-width: 700px) {\n  .adexvz-13 {\n    padding: 18px 16px 14px !important;\n  }\n\n  .adexvz-13 .az-q:first-of-type {\n    font-size: 15px !important;\n  }\n\n  .adexvz-13 .az-q {\n    font-size: 14px !important;\n  }\n}\n<\/style>\n\n<div class=\"adexvz-13\">\n  <div class=\"az-eyebrow\">\n    <svg viewBox=\"0 0 24 24\" aria-hidden=\"true\" focusable=\"false\">\n      <path d=\"M4 6.5h11\"\/>\n      <path d=\"M4 12h16\"\/>\n      <path d=\"M4 17.5h8\"\/>\n      <circle cx=\"19\" cy=\"6.5\" r=\"2.2\"\/>\n    <\/svg>\n\n    <span>How to defend against it &nbsp;&middot;&nbsp; Expert comment<\/span>\n  <\/div>\n\n  <p class=\"az-q\">The attack itself does not change. The same scanning, the same brute forcing, the same exploits, the same traces it leaves behind, so there is nothing in your defenses that needs rewriting.<\/p>\n\n  <p class=\"az-q\">What changes is speed and volume. A person is no longer the limit on the pace: many targets at once, round the clock, working through options faster than anyone can read an alert. The defenses that suffer are the ones that quietly relied on an attack costing time.<\/p>\n\n  <p class=\"az-q\">The conclusion is a boring one. Ordinary fundamentals start to count for more: automated response instead of manual triage, rate limiting, MFA, and unused entry points closed.<\/p>\n\n  <div class=\"az-by\">\n    <span class=\"az-av\" aria-hidden=\"true\">SM<\/span>\n\n    <span class=\"az-who\">\n      <p class=\"az-name\">\n        <a href=\"https:\/\/www.linkedin.com\/in\/%D1%81%D0%B5%D1%80%D0%B3%D0%B5%D0%B9-%D0%BC%D0%B0%D1%80%D1%82%D1%8C%D1%8F%D0%BD%D0%BE%D0%B2-25945391\/\" target=\"_blank\" rel=\"noopener noreferrer\">Sergey Martianov<\/a>\n      <\/p>\n      <p class=\"az-role\">CPO, ADEX<\/p>\n    <\/span>\n  <\/div>\n<\/div>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"the-economics-of-fake-reputation\">The Economics of Fake Reputation<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Half of what you have read rests on one assumption: that trust signals in open source \u2013 stars, forks, contributors, download counts, a listing in a registry \u2013 mean something.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">However, an April 2026 <a href=\"https:\/\/awesomeagents.ai\/news\/github-fake-stars-investigation\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Awesome Agents investigation<\/a> found that GitHub stars are openly advertised in bulk, at prices low enough that the appearance of traction on a repository costs less than a day of an engineer&#8217;s time.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Researchers from CMU, Socket and NC State (<a href=\"https:\/\/conf.researchr.org\/details\/icse-2026\/icse-2026-research-track\/14\/Six-Million-Suspected-Fake-Stars-on-GitHub-A-Growing-Spiral-of-Popularity-Contests\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">ICSE 2026<\/a>) counted some 6 million suspicious stars across 15,835 repositories, and at the July 2024 peak, 16% of all repositories with star activity were caught up in fake campaigns.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Two cases show how that converts into installs.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>The Oura MCP clone (<\/strong><a href=\"https:\/\/www.straiker.ai\/blog\/how-the-clawdbot-moltbot-ai-assistant-becomes-a-backdoor-for-system-takeover\" target=\"_blank\" rel=\"noreferrer noopener nofollow\"><strong>Straiker STAR Labs<\/strong><\/a><strong>, February 2026).<\/strong> The operators behind SmartLoader cloned the real Oura connector, spent three months building it a reputation with at least five fake GitHub accounts producing fake forks and commit history, then submitted the trojanized version to genuine MCP registries. Anyone searching for Oura MCP saw it in the list beside the original, with nothing to tell them apart. This was an impersonation, the clone was not an Oura product, and on the researcher\u2019s account Oura itself was neither involved nor breached.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>$500,000 through a malicious extension installed in Cursor (<\/strong><a href=\"https:\/\/securelist.com\/open-source-package-for-cursor-ai-turned-into-a-crypto-heist\/116908\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\"><strong>Kaspersky<\/strong><\/a><strong>, July 2025). <\/strong>A Solidity Language extension on Open VSX showed 54,000 downloads, all inflated by bots. The point of the inflation was ranking: you type \u2018solidity\u2019, the fake comes up first, you install it. A day after the takedown the authors reposted it under a near-identical name and drove the counter to about 2 million. One blockchain developer, Kaspersky reports, lost around $500,000. Both Open VSX and Cursor were the distribution route here, the malicious code was published by a third party.<\/p>\n\n\n<div class=\"block__bord\"><div class=\"block__bord_desc\"><p><strong>The conclusion: download and star counts are discovery metrics: they tell you a tool is easy to find, but don\u2019t mean it\u2019s safe.<\/strong><\/p>\n<\/div><\/div>\n<style>\n.block__bord { margin: 32px 0; padding: 1.25em 2.375em;\tborder-radius: 24px; background: rgba(0, 220, 200, 0.20); }\n.block__bord_desc {font-size: 16px !important;font-weight: 400 !important;color: #606060 !important;}\n<\/style>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"why-simply-reading-a-code-doesnt-help\">Why Simply Reading a Code Doesn\u2019t Help?<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">For anything open source that is the right first move: read the SKILL.md, read the tool descriptions, read the code including whatever runs during installation, and look at the permissions being requested. It catches the obvious, and against one vector it is a reliable defense, since ClickFix only works if you go along with it.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">It will not catch the rest though for 4 reasons:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>The entry file is a cover page<\/strong>. SKILL.md points at scripts, packages and outside addresses, and the Oura clone kept its payload in an obfuscated script two steps further down. Malicious code also does not look malicious: a line adding a BCC, sitting inside a package built for sending email, reads as code that sends email, and roughly 300 organizations read past it.<\/li>\n\n\n\n<li><strong>Some of the text is never shown to you at all,<\/strong> because MCP tool descriptions arrive from the server while the agent is working. There is a way around that one: install into a sandbox first, read the descriptions and the code once they land there, and move to your real machine only after.<\/li>\n\n\n\n<li><strong>One reading covers one version<\/strong>. postmark-mcp 1.0.15 was clean and 1.0.16 was not. With the AIR skill the files never changed at all, because what changed was the page at the far end of a link.<\/li>\n\n\n\n<li><strong>Scanners hit the same ceiling<\/strong>. In June 2026, <a href=\"https:\/\/blog.trailofbits.com\/2026\/06\/03\/the-sorry-state-of-skill-distribution\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Trail of Bits<\/a> pushed four malicious skills past ClawHub, Cisco&#8217;s scanner, and skills.sh as those checks stood at the time of the test, using tricks as crude as 100,000 blank lines before the payload. Three of the four took under an hour to build, because a scanner works to fixed rules and an attacker gets unlimited tries.<\/li>\n<\/ul>\n\n\n<div class=\"block__preview\">\n        <a href=\"https:\/\/adex.com\/blog\/biggest-malware-scandals-2025\/\" class=\"block__preview_img\"><img src=\"https:\/\/adex.com\/blog\/wp-content\/uploads\/2026\/02\/adex-biggest-malware-scandals-2025.jpg\" srcset=\"https:\/\/adex.com\/blog\/wp-content\/uploads\/2026\/02\/adex-biggest-malware-scandals-2025.jpg\" sizes=\"100vw\" alt=\"Adex: the biggest malware scandals in 2025\" decoding=\"async\" class=\"lazy\"><\/a>\n    <div class=\"block__preview_box\">\n        <a href=\"https:\/\/adex.com\/blog\/category\/current_risks\/\" class=\"block__preview_box-cat\">Current risks<\/a>        <h3 class=\"block__preview_box-title\" id=\"the-biggest-malware-scandals-in-2025-why-the-fraud-looks-legit\"><a href=\"https:\/\/adex.com\/blog\/biggest-malware-scandals-2025\/\">The Biggest Malware Scandals in 2025: Why The Fraud Looks Legit?\u00a0<\/a><\/h3>\n    <\/div>\n<\/div>\n<style>\n.block__preview {display: flex;align-items: center;justify-content: center; margin: 32px 0;}\n.block__preview a {text-decoration: none;}\n.block__preview_img {min-width: 360px;max-width: 360px;min-height: 188px;width: 100%;height: 100%;}\n.block__preview_img img {width: 100%;height: 100%;}\n.block__preview_box {margin-left: 40px;max-width: 360px;}\n.block__preview_box-cat {color: #00B8A7 !important;font-weight: 600;font-size: 12px;line-height: 16px;text-transform: uppercase; display: block; margin-bottom: 4px;}\n.block__preview_box-cat:hover {color: #FE645A !important; text-decoration: none !important;}\n.block__preview_box-title {font-size: 20px;font-weight: 700;line-height: 24px;color: #0B172D;}\n.block__preview_box-title a {color: #0B172D !important;}\n.block__preview_box-title a:hover {color: #FE645A !important;}\n@media screen and (max-width: 768px) {.block__preview {flex-direction: column;}.block__preview_box {max-width: 100%; margin-top: 32px;margin-left: 0px;}.block__preview_img {max-width: 100%;min-width: 100%;min-height: 100%;}}<\/style>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"summary-how-to-protect-your-agent-before-you-install-any-skills-and-files\">Summary: How to Protect Your Agent Before You Install Any Skills and Files<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">These steps reduce risk, but none of them removes it. This is a general checklist for a marketing or ad ops audience, not a security standard, and it does not replace your own organisation&#8217;s security review or its policy on what may be connected to work accounts.<\/p>\n\n\n\n<!-- =========================================================\n     ADEX-STYLE VISUAL: \"What Actually Moves the Risk\" (carousel)\n     Replaces HTML-8 (.adexvz-12) in the AI agent malware article.\n     WORDPRESS: paste this whole block into a \"Custom HTML\" block.\n     All CSS is scoped under .adexvz-14. Works without JS (swipe \/\n     scroll); the small script at the end adds arrows, counter,\n     group chips and keyboard support.\n     ========================================================= -->\n<style>\n.adexvz-14 {\n  --az-ink: #0b0f1c;\n  --az-body: #2a3347;\n  --az-mute: #5b6a8a;\n  --az-faint: #8896b3;\n  --az-line: #dde3ee;\n  --az-hair: #eef1f7;\n  --az-bg: #f7f9fc;\n  --az-teal: #00c9b8;\n  --az-blue: #3b5bdb;\n  --az-amber: #f59f00;\n  --az-red: #e03355;\n\n  display: block !important;\n  width: 100% !important;\n  max-width: 760px !important;\n  margin: 32px auto !important;\n  padding: 24px 0 18px !important;\n  color: var(--az-body) !important;\n  background: var(--az-bg) !important;\n  border: 1px solid var(--az-line) !important;\n  border-radius: 12px !important;\n  font-family: \"Inter\", -apple-system, BlinkMacSystemFont, \"Segoe UI\", Roboto, Arial, sans-serif !important;\n  text-align: left !important;\n  box-sizing: border-box !important;\n  overflow: hidden !important;\n  -webkit-font-smoothing: antialiased;\n}\n.adexvz-14 *, .adexvz-14 *::before, .adexvz-14 *::after { box-sizing: border-box !important; }\n\n\/* head *\/\n.adexvz-14 .az-head { display: flex !important; align-items: flex-start !important; gap: 10px !important; margin: 0 0 16px !important; padding: 0 22px !important; }\n.adexvz-14 .az-logo { display: block !important; flex: 0 0 auto !important; width: 24px !important; height: 28px !important; }\n.adexvz-14 .az-title { margin: 0 !important; padding: 0 !important; border: 0 !important; color: var(--az-ink) !important; font-family: inherit !important; font-size: 16px !important; font-weight: 700 !important; line-height: 1.3 !important; letter-spacing: -0.01em !important; }\n.adexvz-14 .az-sub { margin: 3px 0 0 !important; padding: 0 !important; border: 0 !important; color: var(--az-mute) !important; font-family: inherit !important; font-size: 12.5px !important; font-weight: 400 !important; line-height: 1.5 !important; }\n\n\/* group chips *\/\n.adexvz-14 .az-chips { display: flex !important; flex-wrap: wrap !important; gap: 6px !important; margin: 0 0 14px !important; padding: 0 22px !important; list-style: none !important; }\n.adexvz-14 .az-chip {\n  display: inline-flex !important; align-items: center !important; gap: 6px !important;\n  margin: 0 !important; padding: 6px 10px !important;\n  color: var(--az-mute) !important; background: #ffffff !important;\n  border: 1px solid var(--az-line) !important; border-radius: 999px !important;\n  font-family: inherit !important; font-size: 11.5px !important; font-weight: 600 !important; line-height: 1.2 !important;\n  cursor: pointer !important; transition: border-color .15s, color .15s, background .15s !important;\n  box-shadow: none !important; text-transform: none !important; letter-spacing: 0 !important;\n}\n.adexvz-14 .az-chip:hover { color: var(--az-ink) !important; border-color: var(--az-faint) !important; }\n.adexvz-14 .az-chip:focus-visible { outline: 2px solid var(--az-blue) !important; outline-offset: 2px !important; }\n.adexvz-14 .az-chip i { display: block !important; width: 8px !important; height: 8px !important; border-radius: 50% !important; font-style: normal !important; }\n.adexvz-14 .az-chip.is-on { color: var(--az-ink) !important; border-color: var(--az-ink) !important; }\n\n\/* track *\/\n.adexvz-14 .az-track {\n  display: flex !important; gap: 12px !important;\n  margin: 0 !important; padding: 4px 22px 14px !important;\n  overflow-x: auto !important; overflow-y: hidden !important;\n  scroll-snap-type: x mandatory !important; scroll-padding: 0 22px !important;\n  scroll-behavior: smooth !important; -webkit-overflow-scrolling: touch !important;\n  scrollbar-width: none !important; list-style: none !important;\n}\n.adexvz-14 .az-track::-webkit-scrollbar { display: none !important; }\n.adexvz-14 .az-track:focus-visible { outline: 2px solid var(--az-blue) !important; outline-offset: -2px !important; }\n\n\/* card *\/\n.adexvz-14 .az-card {\n  position: relative !important;\n  display: flex !important; flex-direction: column !important;\n  flex: 0 0 300px !important; min-height: 250px !important;\n  margin: 0 !important; padding: 18px 18px 16px !important;\n  background: #ffffff !important; border: 1px solid var(--az-line) !important; border-radius: 10px !important;\n  border-top: 3px solid var(--c) !important;\n  scroll-snap-align: start !important;\n}\n.adexvz-14 .az-card.g1 { --c: var(--az-teal); --cb: #e6faf7; --ct: #007a6e; }\n.adexvz-14 .az-card.g2 { --c: var(--az-blue); --cb: #eef2ff; --ct: #2f4ac0; }\n.adexvz-14 .az-card.g3 { --c: var(--az-amber); --cb: #fff6e3; --ct: #a36500; }\n.adexvz-14 .az-card.g4 { --c: var(--az-red); --cb: #fff0f3; --ct: #b3203f; }\n\n.adexvz-14 .az-meta { display: flex !important; align-items: center !important; justify-content: space-between !important; gap: 8px !important; margin: 0 0 14px !important; }\n.adexvz-14 .az-grp {\n  display: inline-block !important; padding: 3px 8px !important;\n  color: var(--ct) !important; background: var(--cb) !important; border-radius: 4px !important;\n  font-family: inherit !important; font-size: 10px !important; font-weight: 700 !important; line-height: 1.4 !important;\n  letter-spacing: 0.07em !important; text-transform: uppercase !important;\n}\n.adexvz-14 .az-num { color: var(--az-faint) !important; font-family: inherit !important; font-size: 11px !important; font-weight: 600 !important; line-height: 1.4 !important; font-variant-numeric: tabular-nums !important; }\n.adexvz-14 .az-num b { color: var(--az-ink) !important; font-weight: 700 !important; }\n.adexvz-14 .az-it-t { margin: 0 0 8px !important; padding: 0 !important; border: 0 !important; color: var(--az-ink) !important; font-family: inherit !important; font-size: 15px !important; font-weight: 700 !important; line-height: 1.35 !important; letter-spacing: -0.005em !important; }\n.adexvz-14 .az-it-d { margin: 0 !important; padding: 0 !important; border: 0 !important; color: var(--az-body) !important; font-family: inherit !important; font-size: 13px !important; font-weight: 400 !important; line-height: 1.6 !important; overflow-wrap: anywhere !important; }\n.adexvz-14 .az-it-d a { color: var(--az-ink) !important; border-bottom: 1px solid var(--c) !important; font-family: inherit !important; font-size: inherit !important; font-weight: 600 !important; text-decoration: none !important; }\n.adexvz-14 .az-it-d a:hover { color: var(--ct) !important; }\n.adexvz-14 .az-why { margin: auto 0 0 !important; padding: 12px 0 0 !important; color: var(--az-faint) !important; font-family: inherit !important; font-size: 11px !important; font-weight: 400 !important; line-height: 1.4 !important; }\n.adexvz-14 .az-why::before { content: \"\"; display: block; height: 0; margin: 0 0 12px; border-top: 1px solid var(--az-hair); }\n\n\/* intro card *\/\n.adexvz-14 .az-card.az-intro { --c: var(--az-ink); background: #0b0f1c !important; border-color: #0b0f1c !important; }\n.adexvz-14 .az-intro .az-grp { color: #0b0f1c !important; background: #00c9b8 !important; }\n.adexvz-14 .az-intro .az-it-t { color: #ffffff !important; }\n.adexvz-14 .az-intro .az-it-d { color: #c7cfdf !important; }\n.adexvz-14 .az-intro .az-why { color: #8896b3 !important; }\n.adexvz-14 .az-intro .az-why::before { border-top-color: #232b3d; }\n\n\/* controls *\/\n.adexvz-14 .az-ctrl { display: flex !important; align-items: center !important; gap: 12px !important; margin: 0 !important; padding: 0 22px !important; }\n.adexvz-14 .az-bar { position: relative !important; flex: 1 1 auto !important; height: 3px !important; background: var(--az-line) !important; border-radius: 2px !important; overflow: hidden !important; }\n.adexvz-14 .az-fill { position: absolute !important; top: 0 !important; left: 0 !important; height: 100% !important; width: 0; background: var(--az-ink) !important; border-radius: 2px !important; transition: width .25s ease !important; }\n.adexvz-14 .az-count { color: var(--az-mute) !important; font-family: inherit !important; font-size: 11.5px !important; font-weight: 600 !important; line-height: 1 !important; font-variant-numeric: tabular-nums !important; white-space: nowrap !important; }\n.adexvz-14 .az-arrow {\n  display: flex !important; align-items: center !important; justify-content: center !important;\n  flex: 0 0 auto !important; width: 34px !important; height: 34px !important; margin: 0 !important; padding: 0 !important;\n  color: var(--az-ink) !important; background: #ffffff !important;\n  border: 1px solid var(--az-line) !important; border-radius: 50% !important;\n  cursor: pointer !important; box-shadow: none !important; transition: border-color .15s, opacity .15s !important;\n}\n.adexvz-14 .az-arrow:hover { border-color: var(--az-ink) !important; }\n.adexvz-14 .az-arrow:focus-visible { outline: 2px solid var(--az-blue) !important; outline-offset: 2px !important; }\n.adexvz-14 .az-arrow[disabled] { opacity: .35 !important; cursor: default !important; border-color: var(--az-line) !important; }\n.adexvz-14 .az-arrow svg { display: block !important; width: 16px !important; height: 16px !important; fill: none !important; stroke: currentColor !important; stroke-width: 2 !important; stroke-linecap: round !important; stroke-linejoin: round !important; }\n.adexvz-14 .az-nojs .az-arrow { display: none !important; }\n\n\/* foot *\/\n.adexvz-14 .az-foot { display: flex !important; flex-wrap: wrap !important; align-items: center !important; gap: 8px 16px !important; margin: 16px 0 0 !important; padding: 12px 22px 0 !important; border-top: 1px solid var(--az-line) !important; }\n.adexvz-14 .az-src { margin-left: auto !important; color: #a5afc0 !important; font-family: inherit !important; font-size: 10px !important; font-weight: 400 !important; line-height: 1.4 !important; letter-spacing: 0.03em !important; }\n.adexvz-14 .az-src a { color: #72819d !important; border-bottom: 1px solid rgba(114,129,157,.5) !important; font-family: inherit !important; font-size: inherit !important; font-weight: inherit !important; text-decoration: none !important; }\n.adexvz-14 .az-src a:hover { color: #007a6e !important; }\n.adexvz-14 .az-hint { color: var(--az-faint) !important; font-family: inherit !important; font-size: 10.5px !important; line-height: 1.4 !important; }\n\n@media (max-width: 600px) {\n  .adexvz-14 { padding: 18px 0 14px !important; border-radius: 10px !important; }\n  .adexvz-14 .az-head, .adexvz-14 .az-chips, .adexvz-14 .az-ctrl { padding-left: 16px !important; padding-right: 16px !important; }\n  .adexvz-14 .az-track { padding-left: 16px !important; padding-right: 16px !important; scroll-padding: 0 16px !important; }\n  .adexvz-14 .az-card { flex-basis: 84% !important; min-height: 240px !important; }\n  .adexvz-14 .az-foot { padding-left: 16px !important; padding-right: 16px !important; }\n  .adexvz-14 .az-src { flex-basis: 100% !important; margin-left: 0 !important; }\n}\n@media (prefers-reduced-motion: reduce) {\n  .adexvz-14 .az-track { scroll-behavior: auto !important; }\n  .adexvz-14 .az-fill { transition: none !important; }\n}\n<\/style>\n\n<div class=\"adexvz-14 az-nojs\" role=\"region\" aria-roledescription=\"carousel\" aria-label=\"Seventeen measures that actually move the risk\">\n  <div class=\"az-head\">\n    <svg class=\"az-logo\" viewBox=\"0 0 34 40\" fill=\"none\" aria-hidden=\"true\" focusable=\"false\">\n      <path d=\"M5.31 32.14L17.23 39l11.92-6.87L17.23 20 5.31 32.14ZM4.57 28.5l10.36-10.84-2.77-2.84L4.57 28.5ZM19.55 17.62l10.33 10.88-5.91-10.47 2.47-2.51 7.15 14.04.85-.5V9.19l-4.23-2.45L19.55 17.62ZM15.93 0L0 9.19V29.06l.85.5 10.44-19.48 5.96 6.15 3.32-3.47L17.23 5.48l-1.65 3.01-2.62-2.69L15.93 0ZM18.53 0l4.64 9.08 3.97-4.12L18.53 0Z\" fill=\"#00C9B8\"\/>\n    <\/svg>\n    <div>\n      <p class=\"az-title\">What Actually Moves the Risk<\/p>\n      <p class=\"az-sub\">Seventeen measures, grouped by where each one bites. None of them removes the problem, and together they take away most of what an injected instruction needs.<\/p>\n    <\/div>\n  <\/div>\n\n  <div class=\"az-chips\" aria-label=\"Jump to a group\">\n    <button type=\"button\" class=\"az-chip\" data-go=\"g1\"><i style=\"background:#00c9b8\"><\/i>Before install<\/button>\n    <button type=\"button\" class=\"az-chip\" data-go=\"g2\"><i style=\"background:#3b5bdb\"><\/i>After install<\/button>\n    <button type=\"button\" class=\"az-chip\" data-go=\"g3\"><i style=\"background:#f59f00\"><\/i>Access and exit<\/button>\n    <button type=\"button\" class=\"az-chip\" data-go=\"g4\"><i style=\"background:#e03355\"><\/i>Habits<\/button>\n  <\/div>\n\n  <ol class=\"az-track\" tabindex=\"0\" aria-label=\"Measures, scroll sideways\">\n    <li class=\"az-card az-intro\" aria-roledescription=\"slide\">\n      <div class=\"az-meta\"><span class=\"az-grp\">Start here<\/span><span class=\"az-num\">17 measures<\/span><\/div>\n      <p class=\"az-it-t\">Reading the code comes first, and it is not enough.<\/p>\n      <p class=\"az-it-d\">The entry file is a cover page, malicious code looks like ordinary code, tool descriptions never reach your screen, and one reading only covers one version. Scanners hit the same ceiling: Trail of Bits pushed four malicious skills past three of them in June 2026, three of the four built in under an hour.<\/p>\n      <p class=\"az-why\">Swipe or use the arrows to go through the measures<\/p>\n    <\/li>\n\n    <!-- Group 1: Before You Install -->\n    <li class=\"az-card g1\" data-g=\"g1\" aria-roledescription=\"slide\">\n      <div class=\"az-meta\"><span class=\"az-grp\">Before you install<\/span><span class=\"az-num\"><b>01<\/b> \/ 17<\/span><\/div>\n      <p class=\"az-it-t\">Do not trust the metrics<\/p>\n      <p class=\"az-it-d\">Stars, forks and download counters are for sale. Look at what is expensive to fake: account history, real issues with real answers, a release record, years of activity.<\/p>\n      <p class=\"az-why\">Keeps untrusted tools out<\/p>\n    <\/li>\n    <li class=\"az-card g1\" data-g=\"g1\" aria-roledescription=\"slide\">\n      <div class=\"az-meta\"><span class=\"az-grp\">Before you install<\/span><span class=\"az-num\"><b>02<\/b> \/ 17<\/span><\/div>\n      <p class=\"az-it-t\">Read it, and read all of it<\/p>\n      <p class=\"az-it-d\">SKILL.md, the tool descriptions, the code, whatever executes during installation, and the permissions it asks for.<\/p>\n      <p class=\"az-why\">Keeps untrusted tools out<\/p>\n    <\/li>\n    <li class=\"az-card g1\" data-g=\"g1\" aria-roledescription=\"slide\">\n      <div class=\"az-meta\"><span class=\"az-grp\">Before you install<\/span><span class=\"az-num\"><b>03<\/b> \/ 17<\/span><\/div>\n      <p class=\"az-it-t\">For closed tools, vet the vendor<\/p>\n      <p class=\"az-it-d\">Terms, contract, where the data goes. You cannot read the code, so read the company instead.<\/p>\n      <p class=\"az-why\">Keeps untrusted tools out<\/p>\n    <\/li>\n    <li class=\"az-card g1\" data-g=\"g1\" aria-roledescription=\"slide\">\n      <div class=\"az-meta\"><span class=\"az-grp\">Before you install<\/span><span class=\"az-num\"><b>04<\/b> \/ 17<\/span><\/div>\n      <p class=\"az-it-t\">Put it in a sandbox first<\/p>\n      <p class=\"az-it-d\">An isolated machine with none of your real files, keys or access. It is also where you finally get to read what was invisible before installing.<\/p>\n      <p class=\"az-why\">Keeps untrusted tools out<\/p>\n    <\/li>\n    <li class=\"az-card g1\" data-g=\"g1\" aria-roledescription=\"slide\">\n      <div class=\"az-meta\"><span class=\"az-grp\">Before you install<\/span><span class=\"az-num\"><b>05<\/b> \/ 17<\/span><\/div>\n      <p class=\"az-it-t\">Keep a whitelist, starting with an inventory<\/p>\n      <p class=\"az-it-d\">A vetted catalog beats free installation, and you cannot protect what you cannot see. Finding out what is already installed is usually the unpleasant part.<\/p>\n      <p class=\"az-why\">Keeps untrusted tools out<\/p>\n    <\/li>\n\n    <!-- Group 2: Keep Your Approval Meaningful -->\n    <li class=\"az-card g2\" data-g=\"g2\" aria-roledescription=\"slide\">\n      <div class=\"az-meta\"><span class=\"az-grp\">Keep approval meaningful<\/span><span class=\"az-num\"><b>06<\/b> \/ 17<\/span><\/div>\n      <p class=\"az-it-t\">Pin versions, and update deliberately<\/p>\n      <p class=\"az-it-d\">Approval covers the version you saw. Auto-update off for anything with broad permissions, and treat it as a warning sign when a tool asks for more access after an update or starts reaching places it never reached before.<\/p>\n      <p class=\"az-why\">Closes the rug pull window<\/p>\n    <\/li>\n    <li class=\"az-card g2\" data-g=\"g2\" aria-roledescription=\"slide\">\n      <div class=\"az-meta\"><span class=\"az-grp\">Keep approval meaningful<\/span><span class=\"az-num\"><b>07<\/b> \/ 17<\/span><\/div>\n      <p class=\"az-it-t\">Keep the client itself updated<\/p>\n      <p class=\"az-it-d\">MCPoison was fixed by making any config change require fresh approval. Older clients simply do not have that protection.<\/p>\n      <p class=\"az-why\">Closes the rug pull window<\/p>\n    <\/li>\n    <li class=\"az-card g2\" data-g=\"g2\" aria-roledescription=\"slide\">\n      <div class=\"az-meta\"><span class=\"az-grp\">Keep approval meaningful<\/span><span class=\"az-num\"><b>08<\/b> \/ 17<\/span><\/div>\n      <p class=\"az-it-t\">Scan configurations<\/p>\n      <p class=\"az-it-d\"><a href=\"https:\/\/invariantlabs-ai.github.io\/docs\/mcp-scan\/\" target=\"_blank\" rel=\"noopener noreferrer\">mcp-scan<\/a> pins tool descriptions by hashing them, so a rewritten one shows up immediately. The feature is called Tool Pinning. Cisco AI Defense has skill-scanner, and there are Semgrep rules. A filter rather than a guarantee.<\/p>\n      <p class=\"az-why\">Closes the rug pull window<\/p>\n    <\/li>\n\n    <!-- Group 3: Take Away What the Instruction Needs -->\n    <li class=\"az-card g3\" data-g=\"g3\" aria-roledescription=\"slide\">\n      <div class=\"az-meta\"><span class=\"az-grp\">Take away what it needs<\/span><span class=\"az-num\"><b>09<\/b> \/ 17<\/span><\/div>\n      <p class=\"az-it-t\">Least privilege<\/p>\n      <p class=\"az-it-d\">Read-only access to databases, repo-scoped tokens instead of broad ones, a limited slice of the filesystem, and a container with no SSH keys or cloud credentials sitting next to it.<\/p>\n      <p class=\"az-why\">Breaks the lethal trifecta<\/p>\n    <\/li>\n    <li class=\"az-card g3\" data-g=\"g3\" aria-roledescription=\"slide\">\n      <div class=\"az-meta\"><span class=\"az-grp\">Take away what it needs<\/span><span class=\"az-num\"><b>10<\/b> \/ 17<\/span><\/div>\n      <p class=\"az-it-t\">A separate browser profile and test keys<\/p>\n      <p class=\"az-it-d\">The project folder, not your whole home directory. A fresh profile, not the one holding every logged-in session. Test credentials, not production ones.<\/p>\n      <p class=\"az-why\">Breaks the lethal trifecta<\/p>\n    <\/li>\n    <li class=\"az-card g3\" data-g=\"g3\" aria-roledescription=\"slide\">\n      <div class=\"az-meta\"><span class=\"az-grp\">Take away what it needs<\/span><span class=\"az-num\"><b>11<\/b> \/ 17<\/span><\/div>\n      <p class=\"az-it-t\">Let it out only where it needs to go<\/p>\n      <p class=\"az-it-d\">Allow outgoing connections to the domains the job requires, and to nothing else.<\/p>\n      <p class=\"az-why\">Breaks the lethal trifecta<\/p>\n    <\/li>\n    <li class=\"az-card g3\" data-g=\"g3\" aria-roledescription=\"slide\">\n      <div class=\"az-meta\"><span class=\"az-grp\">Take away what it needs<\/span><span class=\"az-num\"><b>12<\/b> \/ 17<\/span><\/div>\n      <p class=\"az-it-t\">Never turn on \u201calways allow\u201d<\/p>\n      <p class=\"az-it-d\">Confirm anything that leaves: an email, a commit, a write to an external service. And keep sessions apart, so reviewing someone\u2019s repository and working with your own mail never share one.<\/p>\n      <p class=\"az-why\">Breaks the lethal trifecta<\/p>\n    <\/li>\n\n    <!-- Group 4: Watch, and Do Not Play Along -->\n    <li class=\"az-card g4\" data-g=\"g4\" aria-roledescription=\"slide\">\n      <div class=\"az-meta\"><span class=\"az-grp\">Watch, don\u2019t play along<\/span><span class=\"az-num\"><b>13<\/b> \/ 17<\/span><\/div>\n      <p class=\"az-it-t\">Expand the tool-call blocks<\/p>\n      <p class=\"az-it-d\">Almost every client shows them collapsed. Opened up, they name the tool, the arguments and the result, so a claimed action with no matching call never happened. The limit: a log shows a tool ran, not what it did next.<\/p>\n      <p class=\"az-why\">Covers what the agent will not tell you<\/p>\n    <\/li>\n    <li class=\"az-card g4\" data-g=\"g4\" aria-roledescription=\"slide\">\n      <div class=\"az-meta\"><span class=\"az-grp\">Watch, don\u2019t play along<\/span><span class=\"az-num\"><b>14<\/b> \/ 17<\/span><\/div>\n      <p class=\"az-it-t\">Do not click \u201ctrust this folder\u201d on reflex<\/p>\n      <p class=\"az-it-d\">Editors ask before running anything from an unfamiliar project, and restricted mode exists for exactly this. Stay in it while you are only reading someone else\u2019s code.<\/p>\n      <p class=\"az-why\">Covers what the agent will not tell you<\/p>\n    <\/li>\n    <li class=\"az-card g4\" data-g=\"g4\" aria-roledescription=\"slide\">\n      <div class=\"az-meta\"><span class=\"az-grp\">Watch, don\u2019t play along<\/span><span class=\"az-num\"><b>15<\/b> \/ 17<\/span><\/div>\n      <p class=\"az-it-t\">Never copy a command out of a README<\/p>\n      <p class=\"az-it-d\">The ClickFix vector, and going by ClawHavoc, the most productive one in this article. Also the only one you beat by simply not playing along.<\/p>\n      <p class=\"az-why\">Covers what the agent will not tell you<\/p>\n    <\/li>\n    <li class=\"az-card g4\" data-g=\"g4\" aria-roledescription=\"slide\">\n      <div class=\"az-meta\"><span class=\"az-grp\">Watch, don\u2019t play along<\/span><span class=\"az-num\"><b>16<\/b> \/ 17<\/span><\/div>\n      <p class=\"az-it-t\">Run the boring baseline<\/p>\n      <p class=\"az-it-d\">A model-driven attack is the same attack at higher speed and volume, so ordinary hygiene counts for more: MFA, rate limiting, automated response instead of manual triage, unused entry points closed.<\/p>\n      <p class=\"az-why\">Covers what the agent will not tell you<\/p>\n    <\/li>\n    <li class=\"az-card g4\" data-g=\"g4\" aria-roledescription=\"slide\">\n      <div class=\"az-meta\"><span class=\"az-grp\">Watch, don\u2019t play along<\/span><span class=\"az-num\"><b>17<\/b> \/ 17<\/span><\/div>\n      <p class=\"az-it-t\">Lean on the frameworks<\/p>\n      <p class=\"az-it-d\">OWASP Top 10 for LLM Applications, OWASP Top 10 for Agentic Applications (December 2025), <a href=\"https:\/\/owasp.org\/www-project-agentic-skills-top-10\/\" target=\"_blank\" rel=\"noopener noreferrer\">OWASP Agentic Skills Top 10<\/a> \/ AST10 (draft, in public review).<\/p>\n      <p class=\"az-why\">Covers what the agent will not tell you<\/p>\n    <\/li>\n  <\/ol>\n\n  <div class=\"az-ctrl\">\n    <button type=\"button\" class=\"az-arrow az-prev\" aria-label=\"Previous measure\">\n      <svg viewBox=\"0 0 24 24\" aria-hidden=\"true\" focusable=\"false\"><path d=\"M15 5l-7 7 7 7\"\/><\/svg>\n    <\/button>\n    <div class=\"az-bar\" aria-hidden=\"true\"><span class=\"az-fill\"><\/span><\/div>\n    <span class=\"az-count\" aria-live=\"polite\">Intro<\/span>\n    <button type=\"button\" class=\"az-arrow az-next\" aria-label=\"Next measure\">\n      <svg viewBox=\"0 0 24 24\" aria-hidden=\"true\" focusable=\"false\"><path d=\"M9 5l7 7-7 7\"\/><\/svg>\n    <\/button>\n  <\/div>\n\n  <div class=\"az-foot\">\n    <span class=\"az-hint\">Swipe or scroll sideways<\/span>\n    <span class=\"az-src\">\n      Expert commentary:\n      <a href=\"https:\/\/www.linkedin.com\/in\/%D1%81%D0%B5%D1%80%D0%B3%D0%B5%D0%B9-%D0%BC%D0%B0%D1%80%D1%82%D1%8C%D1%8F%D0%BD%D0%BE%D0%B2-25945391\/\" target=\"_blank\" rel=\"noopener noreferrer\">Sergey Martianov<\/a>\n      &nbsp;\u00b7&nbsp; Frameworks per OWASP\n    <\/span>\n  <\/div>\n<\/div>\n\n<script>\n(function () {\n  var roots = document.querySelectorAll('.adexvz-14.az-nojs');\n  Array.prototype.forEach.call(roots, function (root) {\n    root.classList.remove('az-nojs');\n    var track = root.querySelector('.az-track');\n    var cards = Array.prototype.slice.call(track.querySelectorAll('.az-card'));\n    var prev = root.querySelector('.az-prev');\n    var next = root.querySelector('.az-next');\n    var fill = root.querySelector('.az-fill');\n    var count = root.querySelector('.az-count');\n    var chips = Array.prototype.slice.call(root.querySelectorAll('.az-chip'));\n    var total = cards.length - 1; \/\/ measures, without the intro card\n\n    function current() {\n      var x = track.scrollLeft, best = 0, bestD = Infinity, pad = cards[0].offsetLeft;\n      cards.forEach(function (c, i) {\n        var d = Math.abs(c.offsetLeft - pad - x);\n        if (d < bestD) { bestD = d; best = i; }\n      });\n      if (track.scrollLeft + track.clientWidth >= track.scrollWidth - 4) best = cards.length - 1;\n      return best;\n    }\n    function go(i) {\n      i = Math.max(0, Math.min(cards.length - 1, i));\n      track.scrollTo({ left: cards[i].offsetLeft - cards[0].offsetLeft, behavior: 'smooth' });\n    }\n    function update() {\n      var i = current();\n      prev.disabled = i === 0;\n      next.disabled = track.scrollLeft + track.clientWidth >= track.scrollWidth - 4;\n      fill.style.width = (i \/ total * 100) + '%';\n      count.textContent = i === 0 ? 'Intro' : (i < 10 ? '0' + i : i) + ' \/ ' + total;\n      var g = cards[i].getAttribute('data-g');\n      chips.forEach(function (ch) { ch.classList.toggle('is-on', ch.getAttribute('data-go') === g); });\n    }\n    prev.addEventListener('click', function () { go(current() - 1); });\n    next.addEventListener('click', function () { go(current() + 1); });\n    chips.forEach(function (ch) {\n      ch.addEventListener('click', function () {\n        var g = ch.getAttribute('data-go');\n        for (var i = 0; i < cards.length; i++) if (cards[i].getAttribute('data-g') === g) { go(i); break; }\n      });\n    });\n    track.addEventListener('keydown', function (e) {\n      if (e.key === 'ArrowRight') { e.preventDefault(); go(current() + 1); }\n      if (e.key === 'ArrowLeft') { e.preventDefault(); go(current() - 1); }\n    });\n    var t;\n    track.addEventListener('scroll', function () { clearTimeout(t); t = setTimeout(update, 60); }, { passive: true });\n    window.addEventListener('resize', update);\n    update();\n  });\n})();\n<\/script>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"where-this-leaves-you\">Where This Leaves You<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">All of this has happened before. npm is the catalog developers install ready-made code from, the reason most apps today are assembled rather than written from scratch, and ten years ago it worked the way skill registries work now. What fixed it came from the platforms rather than from users reading more carefully: mandatory two-factor for maintainers, trusted publishing, signed provenance.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Malicious package detections across the open-source ecosystem rose 73% in 2025 overall \u2013 <a href=\"https:\/\/www.reversinglabs.com\/press-releases\/reversinglabs-2026-software-supply-chain-security-report-identifies-73-increase-in-malicious-open-source-packages\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">while on PyPI and NuGet<\/a>, the two registries that rolled out mandatory 2FA, detections fell 43% and 60% over the same period, according to the same report.<\/p>\n\n\n<div class=\"block__bord\"><div class=\"block__bord_desc\"><p>Two things are different now. Skill registries are covering in months what npm covered in years, so we are sitting in the gap between a visible problem and the controls that answer it. And an npm library runs inside one program, while a skill runs with the permissions of whoever installed it: mail, repositories, databases, keys.<\/p>\n<\/div><\/div>\n<style>\n.block__bord { margin: 32px 0; padding: 1.25em 2.375em;\tborder-radius: 24px; background: rgba(0, 220, 200, 0.20); }\n.block__bord_desc {font-size: 16px !important;font-weight: 400 !important;color: #606060 !important;}\n<\/style>\n\n\n\n<p class=\"wp-block-paragraph\">Ad tech is catching the same trust problem that just hit GitHub and npm. Media buyers and ad ops teams are now plugging AI agents, reporting copilots, and campaign tools into their reporting and campaign workflows using the same kind of third-party skills and MCP connectors described above. If someone on a marketing team installs a poisoned campaign reporting or creative generation skill, that's a supply-chain risk to ad spend and advertiser data, the same way postmark-mcp put password resets at risk. The only difference is whose credentials leak \u2013&nbsp; an ad account instead of an email inbox. When a number decides what gets installed, the number has to be verified by the platform rather than trusted by the user. That is the standard we hold our own supply to, and it is the question worth asking of any tool that is about to be given access to an ad account.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This article summarises security research published by third parties and is provided for general information only. It is not security advice, not a legal opinion, and not an assessment of any product, vendor, package or registry named in it. All findings, figures and vulnerability statuses are as reported by the cited sources on their publication dates and may have changed. Third-party names and trademarks are used for identification only. Consult your own security team before installing or connecting third-party skills or MCP servers.<\/p>\n\n\n    <div class=\"block__buttons\">\n        <a href=\"https:\/\/app.adex.com\/auth\/login\" class=\"block__buttons_btn\">JOIN ADEX<\/a>    <\/div>\n<style>\n    .block__buttons {\n        text-align: center;\n    }\n\n    .block__buttons_btn {\n        background-color: rgba(254, 100, 90, 1) !important;\n        border-radius: 200px !important;\n        padding: 16px 24px !important;\n        font-weight: 600 !important;\n        font-size: 18px !important;\n        line-height: 24px !important;\n        text-align: center !important;\n        display: inline-block !important;\n        color: #fff !important;\n        text-decoration: none !important;\n        text-transform: uppercase !important;\n    }\n\n    .block__buttons_btn:hover {\n        color: rgba(11, 31, 58, 1) !important;\n    }\n<\/style>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n","protected":false},"excerpt":{"rendered":"<p>What if your AI agent recommends malware as the perfect tool? See how fake repositories, poisoned skills, and MCP servers exploit trust\u2014and what to check before installing anything.<\/p>\n","protected":false},"author":8,"featured_media":6173,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[4],"tags":[16,17],"class_list":["post-6161","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-current_risks","tag-threat","tag-virus"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.4 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>AI Agent Attacks: How Trusted Tools Deliver Malware<\/title>\n<meta name=\"description\" content=\"An AI agent can recommend poisoned skills, expose data, or run malware. See how attacks work and what to check before installing a tool.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/adex.com\/blog\/ai-agent-attackers-delivery-boy\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"AI Agent Attacks: How Trusted Tools Deliver Malware\" \/>\n<meta property=\"og:description\" content=\"An AI agent can recommend poisoned skills, expose data, or run malware. See how attacks work and what to check before installing a tool.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/adex.com\/blog\/ai-agent-attackers-delivery-boy\/\" \/>\n<meta property=\"og:site_name\" content=\"ADEX\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/adexsaas\/\" \/>\n<meta property=\"article:published_time\" content=\"2026-09-24T13:17:31+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-09-24T13:22:03+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/adex.com\/blog\/wp-content\/uploads\/2026\/09\/Adex-AI-Agent-Malware.png\" \/>\n\t<meta property=\"og:image:width\" content=\"1200\" \/>\n\t<meta property=\"og:image:height\" content=\"628\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"Olya Mikheeva\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@adexsaas\" \/>\n<meta name=\"twitter:site\" content=\"@adexsaas\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Olya Mikheeva\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"27 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/adex.com\\\/blog\\\/ai-agent-attackers-delivery-boy\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/adex.com\\\/blog\\\/ai-agent-attackers-delivery-boy\\\/\"},\"author\":{\"name\":\"Olya Mikheeva\",\"@id\":\"https:\\\/\\\/adex.com\\\/blog\\\/#\\\/schema\\\/person\\\/c5794aef7aa28987e7019a804390ee3a\"},\"headline\":\"Do Not Mention This to the User: How an AI Agent Can Turn Into the Attacker&#8217;s Delivery Boy\",\"datePublished\":\"2026-09-24T13:17:31+00:00\",\"dateModified\":\"2026-09-24T13:22:03+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/adex.com\\\/blog\\\/ai-agent-attackers-delivery-boy\\\/\"},\"wordCount\":6040,\"publisher\":{\"@id\":\"https:\\\/\\\/adex.com\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/adex.com\\\/blog\\\/ai-agent-attackers-delivery-boy\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/adex.com\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/Adex-AI-Agent-Malware.png\",\"keywords\":[\"Threat\",\"Virus\"],\"articleSection\":[\"Current risks\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/adex.com\\\/blog\\\/ai-agent-attackers-delivery-boy\\\/\",\"url\":\"https:\\\/\\\/adex.com\\\/blog\\\/ai-agent-attackers-delivery-boy\\\/\",\"name\":\"AI Agent Attacks: How Trusted Tools Deliver Malware\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/adex.com\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/adex.com\\\/blog\\\/ai-agent-attackers-delivery-boy\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/adex.com\\\/blog\\\/ai-agent-attackers-delivery-boy\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/adex.com\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/Adex-AI-Agent-Malware.png\",\"datePublished\":\"2026-09-24T13:17:31+00:00\",\"dateModified\":\"2026-09-24T13:22:03+00:00\",\"description\":\"An AI agent can recommend poisoned skills, expose data, or run malware. See how attacks work and what to check before installing a tool.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/adex.com\\\/blog\\\/ai-agent-attackers-delivery-boy\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/adex.com\\\/blog\\\/ai-agent-attackers-delivery-boy\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/adex.com\\\/blog\\\/ai-agent-attackers-delivery-boy\\\/#primaryimage\",\"url\":\"https:\\\/\\\/adex.com\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/Adex-AI-Agent-Malware.png\",\"contentUrl\":\"https:\\\/\\\/adex.com\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/Adex-AI-Agent-Malware.png\",\"width\":1200,\"height\":628,\"caption\":\"Adex \u2013 AI agent delivering malware through malicious skills and MCP servers.\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/adex.com\\\/blog\\\/ai-agent-attackers-delivery-boy\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/adex.com\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Do Not Mention This to the User: How an AI Agent Can Turn Into the Attacker&#8217;s Delivery Boy\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/adex.com\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/adex.com\\\/blog\\\/\",\"name\":\"ADEX - Ad Fraud & Invalid Traffic Prevention Platform\",\"description\":\"\",\"publisher\":{\"@id\":\"https:\\\/\\\/adex.com\\\/blog\\\/#organization\"},\"alternateName\":\"ADEX\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/adex.com\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/adex.com\\\/blog\\\/#organization\",\"name\":\"ADEX - Ad Fraud & Invalid Traffic Prevention Platform\",\"url\":\"https:\\\/\\\/adex.com\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/adex.com\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/adex.com\\\/blog\\\/wp-content\\\/uploads\\\/2022\\\/05\\\/CDD2258_copy-48-1.svg\",\"contentUrl\":\"https:\\\/\\\/adex.com\\\/blog\\\/wp-content\\\/uploads\\\/2022\\\/05\\\/CDD2258_copy-48-1.svg\",\"width\":148,\"height\":30,\"caption\":\"ADEX - Ad Fraud & Invalid Traffic Prevention Platform\"},\"image\":{\"@id\":\"https:\\\/\\\/adex.com\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/www.facebook.com\\\/adexsaas\\\/\",\"https:\\\/\\\/x.com\\\/adexsaas\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/adex.com\\\/blog\\\/#\\\/schema\\\/person\\\/c5794aef7aa28987e7019a804390ee3a\",\"name\":\"Olya Mikheeva\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/7e1ca40f4b08b576bd7c51e8946605febbcaa99bf482f69ead517b1cd512de42?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/7e1ca40f4b08b576bd7c51e8946605febbcaa99bf482f69ead517b1cd512de42?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/7e1ca40f4b08b576bd7c51e8946605febbcaa99bf482f69ead517b1cd512de42?s=96&d=mm&r=g\",\"caption\":\"Olya Mikheeva\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"AI Agent Attacks: How Trusted Tools Deliver Malware","description":"An AI agent can recommend poisoned skills, expose data, or run malware. See how attacks work and what to check before installing a tool.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/adex.com\/blog\/ai-agent-attackers-delivery-boy\/","og_locale":"en_US","og_type":"article","og_title":"AI Agent Attacks: How Trusted Tools Deliver Malware","og_description":"An AI agent can recommend poisoned skills, expose data, or run malware. See how attacks work and what to check before installing a tool.","og_url":"https:\/\/adex.com\/blog\/ai-agent-attackers-delivery-boy\/","og_site_name":"ADEX","article_publisher":"https:\/\/www.facebook.com\/adexsaas\/","article_published_time":"2026-09-24T13:17:31+00:00","article_modified_time":"2026-09-24T13:22:03+00:00","og_image":[{"width":1200,"height":628,"url":"https:\/\/adex.com\/blog\/wp-content\/uploads\/2026\/09\/Adex-AI-Agent-Malware.png","type":"image\/png"}],"author":"Olya Mikheeva","twitter_card":"summary_large_image","twitter_creator":"@adexsaas","twitter_site":"@adexsaas","twitter_misc":{"Written by":"Olya Mikheeva","Est. reading time":"27 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/adex.com\/blog\/ai-agent-attackers-delivery-boy\/#article","isPartOf":{"@id":"https:\/\/adex.com\/blog\/ai-agent-attackers-delivery-boy\/"},"author":{"name":"Olya Mikheeva","@id":"https:\/\/adex.com\/blog\/#\/schema\/person\/c5794aef7aa28987e7019a804390ee3a"},"headline":"Do Not Mention This to the User: How an AI Agent Can Turn Into the Attacker&#8217;s Delivery Boy","datePublished":"2026-09-24T13:17:31+00:00","dateModified":"2026-09-24T13:22:03+00:00","mainEntityOfPage":{"@id":"https:\/\/adex.com\/blog\/ai-agent-attackers-delivery-boy\/"},"wordCount":6040,"publisher":{"@id":"https:\/\/adex.com\/blog\/#organization"},"image":{"@id":"https:\/\/adex.com\/blog\/ai-agent-attackers-delivery-boy\/#primaryimage"},"thumbnailUrl":"https:\/\/adex.com\/blog\/wp-content\/uploads\/2026\/09\/Adex-AI-Agent-Malware.png","keywords":["Threat","Virus"],"articleSection":["Current risks"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/adex.com\/blog\/ai-agent-attackers-delivery-boy\/","url":"https:\/\/adex.com\/blog\/ai-agent-attackers-delivery-boy\/","name":"AI Agent Attacks: How Trusted Tools Deliver Malware","isPartOf":{"@id":"https:\/\/adex.com\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/adex.com\/blog\/ai-agent-attackers-delivery-boy\/#primaryimage"},"image":{"@id":"https:\/\/adex.com\/blog\/ai-agent-attackers-delivery-boy\/#primaryimage"},"thumbnailUrl":"https:\/\/adex.com\/blog\/wp-content\/uploads\/2026\/09\/Adex-AI-Agent-Malware.png","datePublished":"2026-09-24T13:17:31+00:00","dateModified":"2026-09-24T13:22:03+00:00","description":"An AI agent can recommend poisoned skills, expose data, or run malware. See how attacks work and what to check before installing a tool.","breadcrumb":{"@id":"https:\/\/adex.com\/blog\/ai-agent-attackers-delivery-boy\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/adex.com\/blog\/ai-agent-attackers-delivery-boy\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/adex.com\/blog\/ai-agent-attackers-delivery-boy\/#primaryimage","url":"https:\/\/adex.com\/blog\/wp-content\/uploads\/2026\/09\/Adex-AI-Agent-Malware.png","contentUrl":"https:\/\/adex.com\/blog\/wp-content\/uploads\/2026\/09\/Adex-AI-Agent-Malware.png","width":1200,"height":628,"caption":"Adex \u2013 AI agent delivering malware through malicious skills and MCP servers."},{"@type":"BreadcrumbList","@id":"https:\/\/adex.com\/blog\/ai-agent-attackers-delivery-boy\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/adex.com\/blog\/"},{"@type":"ListItem","position":2,"name":"Do Not Mention This to the User: How an AI Agent Can Turn Into the Attacker&#8217;s Delivery Boy"}]},{"@type":"WebSite","@id":"https:\/\/adex.com\/blog\/#website","url":"https:\/\/adex.com\/blog\/","name":"ADEX - Ad Fraud & Invalid Traffic Prevention Platform","description":"","publisher":{"@id":"https:\/\/adex.com\/blog\/#organization"},"alternateName":"ADEX","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/adex.com\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/adex.com\/blog\/#organization","name":"ADEX - Ad Fraud & Invalid Traffic Prevention Platform","url":"https:\/\/adex.com\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/adex.com\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/adex.com\/blog\/wp-content\/uploads\/2022\/05\/CDD2258_copy-48-1.svg","contentUrl":"https:\/\/adex.com\/blog\/wp-content\/uploads\/2022\/05\/CDD2258_copy-48-1.svg","width":148,"height":30,"caption":"ADEX - Ad Fraud & Invalid Traffic Prevention Platform"},"image":{"@id":"https:\/\/adex.com\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/adexsaas\/","https:\/\/x.com\/adexsaas"]},{"@type":"Person","@id":"https:\/\/adex.com\/blog\/#\/schema\/person\/c5794aef7aa28987e7019a804390ee3a","name":"Olya Mikheeva","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/7e1ca40f4b08b576bd7c51e8946605febbcaa99bf482f69ead517b1cd512de42?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/7e1ca40f4b08b576bd7c51e8946605febbcaa99bf482f69ead517b1cd512de42?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/7e1ca40f4b08b576bd7c51e8946605febbcaa99bf482f69ead517b1cd512de42?s=96&d=mm&r=g","caption":"Olya Mikheeva"}}]}},"_links":{"self":[{"href":"https:\/\/adex.com\/blog\/wp-json\/wp\/v2\/posts\/6161","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/adex.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/adex.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/adex.com\/blog\/wp-json\/wp\/v2\/users\/8"}],"replies":[{"embeddable":true,"href":"https:\/\/adex.com\/blog\/wp-json\/wp\/v2\/comments?post=6161"}],"version-history":[{"count":16,"href":"https:\/\/adex.com\/blog\/wp-json\/wp\/v2\/posts\/6161\/revisions"}],"predecessor-version":[{"id":6185,"href":"https:\/\/adex.com\/blog\/wp-json\/wp\/v2\/posts\/6161\/revisions\/6185"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/adex.com\/blog\/wp-json\/wp\/v2\/media\/6173"}],"wp:attachment":[{"href":"https:\/\/adex.com\/blog\/wp-json\/wp\/v2\/media?parent=6161"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/adex.com\/blog\/wp-json\/wp\/v2\/categories?post=6161"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/adex.com\/blog\/wp-json\/wp\/v2\/tags?post=6161"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}