Security researchers have shown that malicious add-on skills for AI coding agents can be packed to look harmless at install time, exposing a trust gap in today’s plugin-style defenses.
A new supply-chain risk in LLM coding agents shows why install-time checks can miss malicious skill packages that only reveal their behavior once execution begins.