AgentPod is building a private, secure device for your AI agent.The AgentPod device is coming.Coming soonBe first
We checked this and rejected itsecurity

Popular GitHub and browser-style MCP skills are being questioned after package-install prompt injection tests: why it is not safe to use

Tests suggest popular AI agent skills can be useful yet still risky, especially when they can install or run software from package names they read.

What happened

On August 27, 2026, Ars Technica reported on controlled research involving Claude Code, Codex, and Hermes. The researchers found that these agents could be pushed into installing or running software packages they did not own after reading agent-facing files that included package names and instructions. A package is a bundle of software that can be downloaded and run. Ars says the researchers then registered some of those unclaimed package names and saw machines contact their server when the agents executed them.

Around the same time, a highly upvoted Reddit thread from August 6 discussed which MCP servers people actually find useful. MCP servers are add-ons that give an AI agent tools such as GitHub access, file access, or browser control. GitHub MCP, filesystem, and browser automation were among the most talked-about options. Users also openly discussed safety tradeoffs, including setups with broad shell access.

What it means for you

If a skill is popular, public, or widely recommended, that does not automatically make it safe. Skills that can read repositories, browse websites, or run commands may be helpful, but they can also act on instructions hidden in files or pages.

What to do instead

Use only the few skills you really need. Prefer read-only access where possible. Be cautious with anything that can install software, run shell commands, or browse and click automatically. Review prompts and approvals before allowing actions. Keep work and personal accounts separate when possible.

AgentPod lists only reviewed, tested skills, but that is still not a promise of zero risk. Treat every new skill as something to evaluate, not trust by default.

Sources:

  • https://arstechnica.com/security/2026/08/claude-codex-and-hermes-installed-unowned-code-inside-corporate-networks/
  • https://www.reddit.com/r/ClaudeAI/comments/1vh0yd3/top_15_mcp_servers_that_are_actually_useful_in/

Source: https://arstechnica.com/security/2026/08/claude-codex-and-hermes-installed-unowned-code-inside-corporate-networks/

We report what our security review found at the time we checked, with the goal of keeping people safe. Projects change; if a maintainer has since fixed this, we are glad to recheck it. Email hello@agentpod.com.

Copied to clipboard. Paste it into your AI (ChatGPT, Claude, or your agent) to add the skill.