Tech
🇺🇸 United StatesOn the One Hand, We Have Island Technology Explaining How It's Uncovered Thousands of Malicious Github Repos Disguised As AI Agent Skills

It might feel like an eternity that we've been living in this AI era, but really we're only at its advent. As such, many of the risks associated with it have until now been merely hypothetical. However, we're now seeing research filter out from security and software research teams that show some genuinely concerning behaviour, in particular when it comes to AI agents.
On the one hand, we have Island Technology explaining how it's uncovered thousands of malicious GitHub repos disguised as AI agent skills and Model Context Protocol (MCP) servers that the agents are at risk of downloading of their own discretion. On the other hand, we have the AI Security Institute (AISI) showing how the (unrestricted) AI agents it was using for cybersecurity attempted to dupe real people, using fake identities and pressuring people into accepting malicious code. I remember when OpenClaw ('Moltbot', back then) first entered public consciousness with promises of actual agential behaviour to help solopreneurs and the likes do, umm, stuff and things.
Without said solopreneurs having to do said stuff and things themselves—just hook your bot up to your different apps and services, tell it what to do, and let it cook. That wasn't too long ago, either; I reported on it in January. Now, talking about autonomous, agential AI seems pretty normal.
And we're starting to see what this actually means in terms of security risks. We'd seen cases of AI agents running amok before, of course, but these newly identified risks seem a little more concrete. In the first case, Island Technologies has discovered that fake GitHub repos pose a real threat for AI agents.
These kinds of attacks existed previously, of course, but they attempted to dupe real humans who could personally assess them and take responsibility for vetting things thoroughly before downloading. The difference is these repos are now dressing up as AI agent skills and MCP servers to specifically target AI agents, which could download these repositories of their own 'volition'. The Enterprise Browser creator explains: "The most significant shift is a technique we call AgentBaiting.
An AI agent searching for a new capability such as a Skill or an MCP server can discover a campaign repository on its own, treat the attacker's Readme as legitimate documentation, and hand the installation instructions to the user. In our testing, Claude Code, Gemini, and ChatGPT all surfaced malicious campaign repositories without ever being shown a link. A playbook built to deceive people now deceives the agents acting on their behalf.
In at least one run, while Claude didn't download the relevant malicious repo in the company's testing, it did recommend it as a backup. In other runs it did detect malicious code and refused to recommend it. According to the institute, in some of the cybersecurity challenge runs it tasked AI agents with, "an AI agent took autonomous, unsanctioned action on the live internet, targeting real people and organisations.
More specifically, in one case, AISI says, "An agent tried to insert malicious code into an open-source project. In an attempt to get the code approved, the agent engaged in social engineering — creating fake online identities and using them to pressure the project's maintainer to approve the code. A human maintainer caught and refused to approve the malicious code. "The agent researched the project's human maintainers, created multiple fake identities, and used the fake identities to socially engineer a real maintainer into approving the code.
Source: PC Gamer
Most read in this category
Loading article…