Modern Malware - Spyware Skills, Hijacked Base URLs, and 1,230+ Leaking API Keys in AI Instruction Files

Mitiga Labs investigated AI instruction files (skills, hooks, AGENTS.md, MCP configs, rules) and found widespread supply-chain risks, including prompt-exfiltration tradecraft, attacker-controlled ANTHROPIC_BASE_URL overrides routing Claude traffic through MITM proxies, permission-bypass defaults, and over 1,230 hardcoded API keys across tens of services. They released Skillgate, a free community scanner with 80+ detection rules across families like direct execution, prompt manipulation, tool poisoning, credential exposure, and obfuscation. The scanner has analyzed 50,000+ files from 7,000+ public repos, using both rule-based detection and an LLM-based reviewer (Gator Agent). The post warns that AI agents treat these files as trusted instructions with zero validation, making them a new malware vector, and recommends scanning all instruction files before agents load them. 

https://www.mitiga.io/blog/malware-in-ai-instruction-files-skillgate

Comments

Popular posts from this blog

Prompt Engineering Demands Rigorous Evaluation

SecObserve: Simplified Vulnerability and License Management for CI/CD Pipelines

Secure Vibe Coding Guide: Best Practices for Writing Secure Code