Toxic Flows: When Your Agent Skill Becomes a Supply Chain Attack

Featuring

  • Snyk

About This Webinar

When a developer installs an AI agent skill, they are making a trust decision they almost certainly do not know they are making. Snyk's ToxicSkills research into 3,000+ skills from ClawHub and skills.sh found that 36% contain security flaws and 13% contain critical issues, including credential theft, backdoor installation, and active prompt injection payloads. And 91% of confirmed malicious skills combine traditional malware with prompt injection in a single artifact.

This is not a theoretical risk. This is a supply chain that is already under active exploitation. In this session, we'll examine three documented attack chains and define what a rigorous defense of the agentic action layer requires.

  1. Scott Bekker

    Host Scott Bekker Webinar Moderator Future B2B

  2. Sonya Moisset

    Featuring Sonya Moisset Staff Security Advocate Snyk

What You'll Learn

  1. A deep dive into how malicious skills operate through recent attacks
  2. Tactics to motivate risks in the AI skill supply chain
  3. Actionable strategies to defend the agentic action layer