news.mlab.sh
Back to the feed
threat-intel

SkillCloak Lets Malicious AI Agent Skills Evade Static Scanners with Self-Extracting Packing

High
Image: The Hacker News
Summary

Researchers at the Hong Kong University of Science and Technology have developed a method to bypass AI coding agent scanners by using self-extracting packing and character substitution to disguise malicious skills. Their research, detailed in a preprint titled "Cloak and Detonate," highlights a significant gap in current security measures, as malicious skills are routinely slipping past scanners. They also created a runtime checker, SKILLDETONATE, that monitors skill behavior at the operating system level to identify attacks, achieving a lower false-positive rate than traditional scanners. The research demonstrates that malicious skills are already prevalent in public marketplaces, and attackers are utilizing the techniques described to evade detection.

Read the full article at The Hacker News

Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data

Report an error
Confirmed errors are fixed and listed on /corrections.