Skill Poisoning

Agent skills package instructions, scripts, and resources that extend what an agent can do. Like browser extensions or open-source packages, they create a supply chain that attackers can target.

Skill poisoning vectors include:

  • Malicious skills: Skills published with hidden harmful instructions or scripts.
  • Compromised updates: Legitimate skills altered in later versions.
  • Marketplace impersonation: Lookalike skills mimicking trusted ones.
  • Embedded prompts: Instructions in skill files that override user intent.
  • Over-permissioned scripts: Bundled code that runs with broad local access.

OWASP launched an Agentic Skills Top 10 to address these risks, reflecting how quickly skill ecosystems have grown across coding and productivity agents.

Defenses include curated skill sources, review of skill contents before installation, signing and integrity checks, and runtime monitoring of what skills cause agents to do.

How PointGuard AI Helps

PointGuard AI Agentic Endpoint Security discovers installed skills, plugins, and MCP servers on managed devices and enforces policy on what agents may install. AI Runtime Guardrails inspect skill-driven instructions and actions at runtime.

Learn More

Watch Blog Video

Follow us on LikedIn

Our Newsletter

Subscribe

Ready to get started?

Our expert team can assess your needs, show you a live demo, and recommend a solution that will save you time and money.