Malicious GitHub repos are posing as AI agent skills and MCP servers: why it is not safe to use
Researchers say thousands of fake GitHub repos are posing as AI agent tools so agents may find, recommend, or install them.
What happened
PC Gamer reported on August 12, 2026 that Island Technology found thousands of malicious GitHub repositories posing as AI agent skills and MCP servers. MCP, or Model Context Protocol, is a way tools can expose functions and data to an AI assistant. According to the report, these repositories were designed to be discovered by AI agents looking for new capabilities, not only by people browsing GitHub.
Island said that in its testing, Claude Code, Gemini, and ChatGPT all surfaced repositories from the campaign without being given a direct link. The article says Island calls this approach "AgentBaiting." In simple terms, the attacker writes a README that looks like normal setup instructions, and the agent may treat it as trustworthy and recommend or install the repo.
What it means for you
If you use an AI agent to find tools, connect services, or add new skills, convenience can create risk. An agent may surface a repository that looks useful but is actually unsafe. This does not mean every repo is bad. It means the usual "looks legitimate" checks may be less reliable when an agent is doing the searching for you.
What to do instead
Ask your agent to explain why it chose a tool before you install or connect it. Prefer official vendor links and well-known registries over random GitHub search results. Review permissions carefully and avoid giving broad access unless you need it. If possible, test new tools in a separate environment first.
If you want a simpler option, AgentPod lists only reviewed, tested skills. That does not remove all risk, but it can reduce the chance of installing something unvetted.
Sources:
- https://www.pcgamer.com/software/ai/welcome-to-the-internet-in-2026-where-ai-agents-are-both-victim-and-attacker-in-malware-wars/
We report what our security review found at the time we checked, with the goal of keeping people safe. Projects change; if a maintainer has since fixed this, we are glad to recheck it. Email hello@agentpod.com.