Agentic Skills | Episode 69
カートのアイテムが多すぎます
カートに追加できませんでした。
ウィッシュリストに追加できませんでした。
ほしい物リストの削除に失敗しました。
ポッドキャストのフォローに失敗しました
ポッドキャストのフォロー解除に失敗しました
-
ナレーター:
-
著者:
Agentic skills can make AI agents more capable and consistent—but they can also introduce serious security risks. This episode explains how skills work, why malicious skills rank as a leading OWASP concern, and how seemingly harmless Markdown instructions can enable credential theft, remote payload delivery, and manipulated recommendations. Real-world examples illustrate how malicious skills can evade scanners and exploit trusted marketplaces. The episode concludes with practical safeguards, including reviewing skill files, watching for external instructions and prompt injection, pinning versions, limiting permissions, and running agents inside isolated environments.
Links:
OWASP Agentic Skills Top 10
Malicious AI Agent Skill Bypasses Security Scans and Seizes Full Control of Over 26,000 Agents
- (00:00) - Agentic Skills and the OWASP Top 10
- (00:23) - Podcast Sponsors: BHIS and Antisyphon Training
- (01:29) - What Is an Agentic Skill?
- (03:13) - Skill Marketplaces and Widespread Adoption
- (03:46) - Why Malicious Skills Are the #1 Risk
- (05:50) - Remote Payloads and External Instructions
- (07:00) - Malicious Skill Takes Control of 26,000 Agents
- (08:09) - Money Radar and Manipulated Recommendations
- (09:20) - How to Evaluate and Use Skills Safely
- (11:08) - Closing Thoughts
Click here to watch this episode on YouTube.
Creators & Guests
- Brian Fehrman - Host
Brought to you by:
Black Hills Information Security
https://www.blackhillsinfosec.com
☯️ Introducing BHIS Fusion Penetration Testing
https://www.blackhillsinfosec.com/fusion-penetration-testing/
Antisyphon Training
https://www.antisyphontraining.com/
Active Countermeasures
https://www.activecountermeasures.com
Wild West Hackin Fest
https://wildwesthackinfest.com
🔗 Register for FREE Infosec Webcasts, Anti-casts & Summits
https://poweredbybhis.com
Click here to view the episode transcript.