skills.sh typosquat skills stole developer secrets after building trust: why it is not safe to use
A skills.sh lookalike campaign built trust, then updated skills to steal developer secrets, and installed copies must be removed by users.
What happened
TechRadar reported on August 7, 2026 that Zenity Labs found a credential-stealing campaign on skills.sh, Vercel’s public registry for AI agent skills. A registry is a public catalog where people can find and install add-ons. According to the report, attackers copied legitimate skills and published lookalike versions with slightly altered names, a tactic known as typosquatting. These skills were initially harmless, then later updated to steal sensitive files and tokens. Tokens are secret strings that let apps access accounts or services.
Zenity said the campaign targeted SSH keys, cloud credentials, Git and package manager tokens, Kubernetes and Docker configs, database credentials, and environment files. One malicious skill family reportedly reached more than 1.7 million aggregate installs. Zenity also said it found dozens of other malicious or dangerous skills, and that about 30% of the dangerous skills abused Claude Code and OpenClaw to install malware. Malware is software designed to harm or secretly control a device. Vercel and Microsoft removed the identified skills, but users who had already installed them were told they must remove them manually.
What it means for you
If you use AI agent skills, a skill that looked safe at first may not stay safe after an update. Removal from a public registry does not uninstall it from your computer.
What to do instead
Check whether you installed any skill from skills.sh and remove anything you do not fully recognize. Review recent skill updates, especially lookalike names. Rotate any exposed secrets such as SSH keys, cloud credentials, and access tokens. Watch for unusual account activity and reinstall from trusted sources only. If you use a curated catalog, prefer one that reviews and tests listed skills. AgentPod says it lists only reviewed, tested skills.
Sources:
- https://www.techradar.com/pro/security/experts-warn-malicious-ai-skills-are-hitting-more-victims-than-ever-with-one-family-amassing-1-7-million-downloads
- https://www.skills.sh/docs
We report what our security review found at the time we checked, with the goal of keeping people safe. Projects change; if a maintainer has since fixed this, we are glad to recheck it. Email hello@agentpod.com.