Sunday, 13 September 2026
8 agent hacks today 7 vs yesterday (1)

claude-skill-antivirus fails to analyze executable files in skill directories

claude-skill-antivirus only scans SKILL.md manifests while ignoring Python source code and other executable artifacts in skill directories, allowing attackers to distribute skills with malicious code that receive a SAFE verdict despite containing unanalyzed payloads.

Disclosed 2 September 2026 · Record updated 13 September 2026

Impact

Malicious skills can be distributed with a trusted SAFE verdict and high trust score while containing executable payloads in unanalyzed files.

Our coverage

No articles linked to this incident yet.

Sources

  1. github.comhttps://github.com/advisories/GHSA-gvgj-r6pg-m42w
  2. github.comhttps://github.com/advisories/GHSA-79wm-x847-7cvg