Zenity Raises $125 Million to Secure the Era of 1 Billion AI Agents

Zenity Labs Discovers Dozens of Malicious AI Agent Skills Evading Detection, Launches AI Total

Zenity Labs Discovers Dozens of Malicious AI Agent Skills Evading Detection, Launches AI Total

New research finds malicious AI agent skills that evade static detection and deliver malware. AI Total dynamically analyzes skills in a contained environment to expose malicious behavior at runtime.

Las Vegas - August 6, 2026 - At Black Hat USA, today revealed new research uncovering dozens of malicious AI agent skills in public registries. The skills expose an emerging AI supply chain risk and are designed to deliver malware, manipulate agent configurations, exfiltrate data and execute attacker-controlled instructions.

To identify these threats, Zenity Labs developed , a free threat intelligence service that dynamically executes AI agent skills inside a contained environment and analyzes their runtime behavior. Unlike static approaches that evaluate a skill based on its code or instructions, AI Total observes what the skill and agent do when the skill is executed.

The research uncovered skills demonstrating multiple types of dangerous behaviors. More than 30% of dangerous identified skills abuse Claude Code and OpenClaw as malware droppers, manipulating the agents to download files from an attacker-controlled endpoint and execute them on the user’s machine. One skill instructs the agent to update its system prompt to install the skill again in case it gets deleted, exhibiting textbook malware behavior. Another uninstalls Claude’s own skill-creator and covertly replaces it with itself, never notifying the user about the update. In one malicious skill, researchers noticed a command directing the agent to install an unverified Python package. Following this lead, they uncovered an extensive typosquatting infrastructure, including hundreds of reserved but empty package names ready for future use.

One malicious skill uncovered during the research amassed more than 250,000 installs while remaining undetected for several months. During that time, it climbed the leaderboard of one of the most popular skill registries and became one of the platform’s top 150 skills, showing how sophisticated attackers can achieve significant adoption before they are identified.

The findings point to a broader expansion of software supply chain risk. For AI agents, the supply chain extends beyond traditional code dependencies to include skills, tools, MCP servers, packages, files and any content on the internet. All are capable of influencing agent behaviors. Compromising any of these components can introduce instructions that manipulate an agent into taking unauthorized or malicious actions.

Why Static Analysis Misses These Threats

Many existing approaches analyze a skill’s code or instructions to determine whether it appears malicious. Zenity Labs found that this approach misses threats whose malicious behavior only emerges during execution. A skill can appear benign while retrieving attacker-controlled instructions from the web, installing malicious packages or triggering harmful agent actions only at runtime.

The Agent Detonation Chamber

Taking inspiration from malware detonation, AI Total is built on a technique Zenity Labs calls the Agent Detonation Chamber. Rather than reading a skill, it runs it. The skill is activated by a live agent inside a contained sandbox, seeded with realistic bait such as credentials and sensitive files, while the system records everything the skill does during runtime: the domains it reaches, the packages it pulls, the files it touches, and every action the agent takes on its behalf. What a skill actually does, compared to what it claims to do, becomes the verdict.

"The most dangerous skills are designed to appear benign and neutralize LLM analysis while hiding malicious behavior that only emerges during execution" said Michael Bargury, CTO and co-founder of Zenity. "AI Total gives defenders a way to see what a skill actually does before trusting it with an AI agent.”

AI Total Available Free to the Security Community

AI Total is available free of charge for security researchers, AI builders and organizations adopting AI agents. Users can submit a skill for dynamic analysis and receive a verdict based on its observed runtime behavior. Zenity Labs plans to extend AI Total to additional components of the AI supply chain.AI Total is available at .

Zenity Labs presented the full research at Black Hat USA 2026.The complete report is available at labs.zenity.io.

Zenity is the first security and governance platform purpose-built for agents spanning SaaS, homegrown platforms (Cloud) and end user devices (Endpoint). Trusted by Fortune 500 enterprises, Zenity helps security teams confidently adopt AI by delivering defense in depth with full-lifecycle coverage, from agent discovery and posture management to real-time detection, inline prevention and response. With an agent-centric approach that prioritizes how agents behave, what they access and which tools they invoke, Zenity eliminates blind spots and enforces consistent policy and controls across environments so organizations can innovate with AI without compromising security. Learn more at www.zenity.io.


All Articles

Secure Your Agents

We’d love to chat with you about how your team can secure and govern AI Agents everywhere.

Get a Demo