The sorry state of skill distribution (opens in new tab)
Public skill marketplaces are being flooded with malicious skills that steal credentials, exfiltrate data, and hijack agents. In response, a segment of the security industry released skill scanners, a new family of tools designed to detect malicious skills before they’re installed. But we tested them, and they don’t work. We recently bypassed , , and all three of the scanners integrated into Why skill security matters Software supply chains have long been the soft underbelly of computer secur...
Read the original article