AI Security Ops

Black Hills Information Security

Agentic Skills | Episode 69

SEP 14, 202611 MIN

Description

Agentic skills can make AI agents more capable and consistent—but they can also introduce serious security risks. This episode explains how skills work, why malicious skills rank as a leading OWASP concern, and how seemingly harmless Markdown instructions can enable credential theft, remote payload delivery, and manipulated recommendations. Real-world examples illustrate how malicious skills can evade scanners and exploit trusted marketplaces. The episode concludes with practical safeguards, including reviewing skill files, watching for external instructions and prompt injection, pinning versions, limiting permissions, and running agents inside isolated environments. Links: OWASP Agentic Skills Top 10 Malicious AI Agent Skill Bypasses Security Scans and Seizes Full Control of Over 26,000 Agents (00:00) - Agentic Skills and the OWASP Top 10 (00:23) - Podcast Sponsors: BHIS and Antisyphon Training (01:29) - What Is an Agentic Skill? (03:13) - Skill Marketplaces and Widespread Adoption (03:46) - Why Malicious Skills Are the #1 Risk (05:50) - Remote Payloads and External Instructions (07:00) - Malicious Skill Takes Control of 26,000 Agents (08:09) - Money Radar and Manipulated Recommendations (09:20) - How to Evaluate and Use Skills Safely (11:08) - Closing Thoughts Click here to watch this episode on YouTube. Creators & Guests Brian Fehrman - Host Brought to you by: Black Hills Information Security  https://www.blackhillsinfosec.com ☯️ Introducing BHIS Fusion Penetration Testing https://www.blackhillsinfosec.com/fusion-penetration-testing/ Antisyphon Training https://www.antisyphontraining.com/ Active Countermeasures https://www.activecountermeasures.com Wild West Hackin Fest https://wildwesthackinfest.com 🔗 Register for FREE Infosec Webcasts, Anti-casts & Summits https://poweredbybhis.com Click here to view the episode transcript.