New free AI Total threat intelligence service dynamically analyzes AI agent skills to expose malicious behavior at runtime
LAS VEGAS--(BUSINESS WIRE)--At Black Hat USA, Zenity Labs today announced new research detailing an active credential-stealing malicious skills campaign distributed through Vercel’s skills.sh. The affected skill family amassed more than 1.7 million aggregate installs, not unique users. The research also uncovered dozens of additional malicious or dangerous skills in public registries. The campaign was quickly disrupted by Zenity and Vercel upon discovery.
To identify and investigate these threats, Zenity Labs developed AI Total, a new free threat intelligence service that dynamically executes AI agent skills inside a contained environment and analyzes their runtime behavior. Unlike static approaches that evaluate a skill based on its code or instructions, AI Total observes what the skill and agent do when the skill is executed.
The campaign targeted users of the popular AI tools Paperclip and Browser Use through typosquatted skills and look-alike repositories. The Paperclip skill family began accumulating installs while its skill files were still clean. Attackers later weaponized the skills by inserting malicious installation instructions that caused AI agents to download and execute attacker-controlled code.
Once executed, the malware searches for sensitive information across developer workstations, continuous integration environments and AI agent workspaces. The targeted data includes SSH keys, cloud credentials, Git and package manager tokens, Kubernetes and Docker configurations, database credentials, infrastructure-as-code credentials, environment files and service account files. The malware packages the stolen information with host metadata and transmits it to attacker-controlled infrastructure.
Beyond the active campaign, Zenity Labs uncovered dozens of additional skills exhibiting malicious or dangerous behavior. More than 30% of identified dangerous skills abuse Claude Code and OpenClaw as malware droppers, manipulating the agents to download files from an attacker-controlled endpoint and execute them on the user’s machine.
One skill instructs the agent to update its system prompt to install the skill again in case it gets deleted, exhibiting textbook malware behavior. Another uninstalls Claude’s own skill-creator and covertly replaces it with itself, never notifying the user about the update. In one malicious skill, researchers noticed a command directing the agent to install an unverified Python package. Following this lead, they uncovered an extensive typosquatting infrastructure, including hundreds of reserved but empty package names ready for future use.
The findings point to a broader expansion of software supply chain risk. For AI agents, the supply chain extends beyond traditional code dependencies to include skills, tools, MCP servers, packages, files and any content on the internet. Each can influence agent behavior. Compromising any of these components can introduce instructions that manipulate an agent into taking unauthorized or malicious actions.
How the Campaign Worked
Zenity Labs identified four methods used to trigger the malware: direct instructions embedded in skills, malicious Python packages, an automated package installation process and code executed during normal Paperclip API use. In one attack path, the malicious command was concealed in a secondary installation document that an agent would retrieve only when Paperclip needed to be installed or started. Benign-looking skills could also refer agents to other skills that ultimately led to remote code execution.
The campaign also exploited a time-of-check to time-of-use weakness in skill marketplaces. The Paperclip skills initially appeared as clean copies of legitimate upstream skills, allowing them to accumulate installs and credibility before the content behind them was modified to deliver malware.
Following notification from Zenity Labs, Vercel and Microsoft/GitHub removed the identified skills, marketplace listings and repositories within 12 hours. However, copied instructions may remain in downstream repositories, aggregators and user systems.
Why Static Analysis Misses These Threats
Many existing approaches analyze a skill’s code or instructions to determine whether it appears malicious. Zenity Labs found that this approach misses threats whose malicious behavior only emerges during execution. A skill can appear benign while retrieving attacker-controlled instructions from the web, installing malicious packages or triggering harmful agent actions only at runtime.
The Agent Detonation Chamber
Taking inspiration from malware detonation, AI Total is built on a technique Zenity Labs calls the Agent Detonation Chamber. Rather than reading a skill, it runs it. A live agent activates the skill inside a contained sandbox seeded with realistic bait, such as credentials and sensitive files. The system records everything the skill does during runtime: the domains it reaches, the packages it pulls, the files it touches and every action the agent takes on its behalf. What a skill actually does compared with what it claims to do determines the verdict.
“The most dangerous skills are designed to appear benign and neutralize LLM analysis while hiding malicious behavior that only emerges during execution,” said Michael Bargury, CTO and co-founder of Zenity. “AI Total gives defenders a way to see what a skill actually does before trusting it with an AI agent.”
AI Total Available Free to the Security Community
AI Total is available free of charge to security researchers, AI builders and organizations adopting AI agents. Users can submit a skill for dynamic analysis and receive a verdict based on its observed runtime behavior. Zenity Labs plans to extend AI Total to additional components of the AI supply chain. AI Total is available at aitotal.io.
Michael Bargury, co-founder and CTO of Zenity, will present the full research at Black Hat USA 2026 during “Promptware EOD: Skillful Agent Detonation” on Thursday, Aug. 6, from 3:35 to 4:15 pm PT. The complete report will be available at labs.zenity.io following the session.
Zenity is the first security and governance platform purpose-built for agents spanning SaaS, homegrown platforms (Cloud) and end user devices (Endpoint). Trusted by Fortune 500 enterprises, Zenity helps security teams confidently adopt AI by delivering defense in depth with full-lifecycle coverage, from agent discovery and posture management to real-time detection, inline prevention and response. With an agent-centric approach that prioritizes how agents behave, what they access and which tools they invoke, Zenity eliminates blind spots and enforces consistent policy and controls across environments so organizations can innovate with AI without compromising security.
Also Read:





