AIR says its fake AI skill passed scanner checks by using a mutable external link, exposing a blind spot in agent skill vetting.

AIR says its fake AI skill passed scanner checks by using a mutable external link, exposing a blind spot in agent skill vetting.

Security firm AIR built a harmless fake skill, got it past Cisco and NVIDIA scanners, and says it reached 26,000 agents, exposing a blind spot in how skills are vetted.

TL;DR what: Security firm AIR planted a fake skill named brand-landingpage that passed...

Security scanners only check what's in the package. Malicious actors are exploiting that narrow view with mutable external links that change after approval—and a single fake skill…