AgentPod is building a private, secure device for your AI agent.The AgentPod device is coming.Coming soonBe first
We checked this and rejected itsecurity

Malicious skills on skills.sh reached 1.7 million installs: why it is not safe to use

A report says malicious skills on skills.sh reached 1.7 million installs and were used to steal keys, tokens, and config files.

What happened

TechRadar reported on August 7, 2026 that Zenity Labs found a credential-stealing campaign on skills.sh, a public registry for AI agent skills run by Vercel. The report says attackers copied legitimate skills, waited until people had downloaded them, and then added hidden instructions to send sensitive files out of the user’s system.

According to the report, the targeted data included SSH keys, cloud credentials, Git and package-manager tokens, Kubernetes and Docker config files, database credentials, environment files, and service-account files. A token is a secret code that lets software access an account or service. Zenity said one malicious skill family alone reached more than 1.7 million total installs. It also reported dozens of other dangerous skills and hundreds of reserved or empty names that could be used later.

Vercel’s documentation says skills.sh does routine security audits, but cannot guarantee every listed skill is safe. It also says users who already installed a bad skill must remove it manually.

What it means for you

If you use an AI agent, a skill can have the same access your agent has. That means a bad skill may be able to read files and secrets stored on your machine or in your development tools.

What to do instead

Install only skills you truly need. Prefer skills from reviewed sources, and remove anything you do not recognize. If you installed a skill from skills.sh, check whether it can access keys, tokens, or config files, then remove suspicious items and rotate exposed secrets. Rotating a secret means replacing it with a new one so the old one stops working.

If you want a smaller trust surface, AgentPod lists only reviewed, tested skills.

Sources:

  • https://www.techradar.com/pro/security/experts-warn-malicious-ai-skills-are-hitting-more-victims-than-ever-with-one-family-amassing-1-7-million-downloads
  • https://www.skills.sh/docs

Source: https://www.techradar.com/pro/security/experts-warn-malicious-ai-skills-are-hitting-more-victims-than-ever-with-one-family-amassing-1-7-million-downloads

We report what our security review found at the time we checked, with the goal of keeping people safe. Projects change; if a maintainer has since fixed this, we are glad to recheck it. Email hello@agentpod.com.

Copied to clipboard. Paste it into your AI (ChatGPT, Claude, or your agent) to add the skill.