The largest automated security audit of AI agent skills to date. 96,096 skills scanned across six registries (OpenClaw, ClawHub, Skills.sh, Hermes Agent, MCP Registry) using 113 ATR detection rules. 1,302 flagged (1.35%), 751 confirmed malware (0.78%) from three coordinated threat actors. Tool description poisoning accounts for 53% of detections. Median scan latency 5.39ms per skill. All findings reported and blacklisted.
Kuan-Hsin Lin (Thu,) studied this question.
Synapse has enriched 5 closely related papers on similar clinical questions. Consider them for comparative context: