HomeSecuritySkillCloak: Malicious AI Skills bypass scanners

SkillCloak: Malicious AI Skills bypass scanners

The SkillCloak proves that malicious AI agent skills can bypass almost any static scanner with surprising ease, according to new research from the Hong Kong University of Science and Technology. The researchers tested the method on eight different scanners and found that their most powerful technique fooled the checks by more than 90 percent. In parallel, the same team developed a detection tool based on behavioral analysis that fills the gap left by static checks.

See also: OpenClaw: Researchers discover 341 malicious ClawHub skills

SkillCloak technique malicious AI agent skills bypass scanners

Skills are small packages — usually a Markdown instruction file along with some scripts — that agents like Claude Code , OpenAI Codex , and OpenClaw load to gain new capabilities. Because a skill is just a bunch of files, the same package can be run on different agents. And it runs with the same privileges as the agent: access to your files, your terminal, your saved passwords. A malicious skill can steal credentials, copy source code, or install a backdoor .

The main line of defense until now has been the skill scanner, which reads a skill’s files before it’s installed and blocks anything that looks dangerous. The research, titled “Cloak and Detonate,” examines whether this defense holds up in practice. The answer is no. Public marketplaces are already full of malicious packages uploaded by unknown users with little oversight.

How SkillCloak Works: Two Bypass Techniques

The SkillCloak rewrites a malicious skill to look clean while behaving exactly the same. It works in two ways. The first, lighter way replaces the characteristic bytes that a scanner detects: replacing a character with a visually similar one from another alphabet (homoglyph substitution), or splitting a malicious command onto a new line so that the scanner pattern no longer matches, but the command is executed normally. This method outperformed most scanners by over 80% and reached 96% in one of them.

See also: OpenClaw AI Agent: Critical vulnerabilities allow prompt injection

SkillCloak - SecNews.gr

The second, more severe method is self-extracting packing: it moves the entire payload to a directory that the scanner skips — such as .git/ — behind a harmless decoder that reconstructs the skill only when the agent executes it. Scanners skip such directories to save time and reduce false positives — and this is precisely the blind spot that the technique exploits. In tests with 1,613 truly malicious skills from ClawHub, a public marketplace, the packing technique outperformed all eight scanners by over 90%, and most by over 99%.

It’s worth noting that cloaking costs the attacker almost nothing: in Claude Code and OpenAI Codex, cloaked skills performed just as well as the originals. Cisco’s scanner, the most powerful one tested, was able to detect 99% of malicious skills before cloaking, but only 10% after it — a dramatic drop that highlights the severity of the problem.

SkillCloak and the backlash: The SKILLDETONATE tool

Since appearance can be tampered with, the researchers propose controlling behavior instead of appearance, through a tool they call SKILLDETONATE. It runs the skill in a sandbox and monitors what it does at the operating system level: what it reads, what it writes, where it sends data. Two ideas make it effective for agents: it monitors sensitive data based on its flow, not its appearance, so base64 or encryption don't confuse it. It also executes the instructions that build a skill only at runtime, right where the payload is hidden by the packing technique.

In controlled tests, SKILLDETONATE detected 97% of attacks while falsely flagging only 2% of safe skills — a lower false positive rate than the scanners it outperforms. In truly malicious skills, it detected 87%. The downside is speed: it takes a few minutes per skill versus a few seconds for a scanner, although it only runs once, before a skill is put into action. The work is still in preprint and has not undergone peer review, while the researchers have published their code.

See also: Fake installers for LetsVPN & QQ Browser distribute Winos 4.0 malware

SkillCloak: Malicious AI Skills bypass scanners

The issue of AI agent skills is becoming increasingly important as these tools are integrated into the daily workflows of developers and businesses. This research highlights that relying on static checks is not enough: dynamic behavioral analysis is required. Users installing skills from public marketplaces should be especially careful, preferring verified publishers and limiting agent permissions to the minimum necessary. Public marketplaces are already full of malicious skills waiting for unsuspecting victims.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS