A growing body of research shows that reusable AI agent skills can be weaponized to steal credentials, pull source code, and plant backdoors while slipping past weaker static checks.
A new build-time control model is trying to spot suspicious behavior where software is assembled, not just in the code that eventually ships.