AI Total
Your Skills Might Be Working For Someone Else
Zenity Labs detonated thousands of publicly available AI agent skills and caught them exfiltrating data, injecting hidden instructions, and running code from servers that no longer exist, none of it flagged by the tools people rely on today. AI Total makes that dynamic scan available to everyone, so teams can see what a skill does before allowing it into use.

Static Analysis Isn't Enough
For decades, the security industry stopped judging malware by reading it. You detonate the file in a contained environment and watch what it does. AI agent skills never got that treatment, and attackers noticed.
A skill is a small, shareable instruction package that tells an AI agent how to do a task, and they are spreading fast across public registries. The tools built to vet them only read them. So attackers write skills that look clean on the page: a harmless looking link that pulls its real instructions from the web only when it runs, a benign looking package that turns hostile the moment it installs. Static analysis sees nothing. The agent runs it anyway.
This is not one bad skill. It is an emerging AI supply chain risk that lives wherever an agent takes in untrusted content and acts on it.
Dozens of Malicious Skills. One Reached 250,000 Machines.
In its first at-scale analysis, Zenity Labs uncovered dozens of malicious AI agent skills sitting in public registries, built to deliver malware, rewrite agent configurations, exfiltrate data, and run attacker-controlled instructions. One had already been installed more than 250,000 times and stayed undetected for months, climbing into the top 150 skills on one of the most popular registries before anyone caught it.
Detonation Chamber:
Where Bad Behavior Can't Hide
Don't Just Read the Skill, Run It
AI Total hands the skill to a live agent inside a contained sandbox and activates it the way a real user would. As it runs, the system captures every layer: the domains the machine reaches, the packages it pulls, the files it touches, and every command, tool call, and action the agent takes on the skill's behalf. The sandbox is seeded with bait, planted credentials and sensitive files, so any skill hunting for secrets outs itself by reaching for them. What the skill actually does, compared to what it claims to do, becomes the verdict.
The Skill That Reached a Quarter Million Machines
One malicious skill racked up more than 250,000 installs and went unnoticed for months, climbing into the top 150 on a leading registry. Popularity is not proof of safety. The most successful attacks earn trust first.
Adoption is not a security signal. The Detonation Chamber is.
The Malware Droppers
More than 30% of the malicious skills abused the agent itself, including Claude Code and OpenClaw, as a malware dropper: instructing it to pull files from an attacker-controlled endpoint and execute them on the user's machine. The payload was never in the skill. It arrived only when the skill ran.
Static analysis saw a clean skill. The Detonation Chamber saw the attack.
The Reinstaller and the Impostor
One skill told the agent to rewrite its own system prompt so the skill would reinstall itself even after it was deleted, textbook malware persistence. Another quietly uninstalled Claude's own skill-creator and replaced it with itself, never telling the user.
These skills were not hijacked. They were designed this way.
Typosquatting Campaign
A single skill carried a command to install an unverified Python package. Following that thread, researchers uncovered an extensive typosquatting operation: hundreds of reserved but empty package names, staged and waiting to be weaponized against every machine that installs a dependent skill.
One skill was the tell. The infrastructure behind it was built for scale.
Secure Your Agents
We’d love to chat with you about how your team can secure and govern AI Agents everywhere.
Get a Demo