
AI skills may look like simple extensions to an agent. Lineaje research shows malicious ones can behave more like multi-purpose attack tools.
Across 75 unique malicious skill URLs, Lineaje analyzed 5,505 malicious skill-category records. The average malicious skill was associated with 9.44 distinct malicious categories, with a median of 9 and a maximum of 18.
Think of a malicious AI skill as a Swiss Army knife for attack: one skill can bring together multiple capabilities that would traditionally be treated as separate security concerns.
The most prevalent capability classes found across the malicious skills analyzed included:
And those are only the most prevalent capability classes. Lineaje's analysis also identified categories including privilege escalation, persistence, prompt injection, credential theft, supply chain attacks, defense evasion, system tampering, and more.
Skills can contain prompts, tool definitions, scripts, commands, workflows, package instructions, and execution logic. They can influence agent behavior, invoke tools, access context, install packages, execute commands, or move data.
That changes how organizations need to think about them.
If a skill can execute like software, access resources like software, and carry malicious behavior like software, it needs to be secured like software.
Traditional software supply chain security focuses on code, open-source packages, dependencies, containers, and build artifacts.
Agentic AI adds another layer: skills, agents, MCP servers, RAG pipelines, and tools. Modern application risk now spans sourced, built, AI, and runtime artifacts—not repositories alone.
For AI skills specifically, that means applying software supply chain controls including sourcing policy, scanning, signing, approval, provenance, runtime constraints, and trusted replacement paths.
One malicious AI skill can carry an arsenal of attack behaviors.
The average skill in Lineaje's malicious sample was associated with 9.44 malicious categories. The maximum was 18.
As AI agents become part of the application, their skills become part of the software supply chain—and part of the attack surface.
If it can influence what an AI agent executes, accesses, or trusts, it needs to be secured like software.
Source: Build Secure or Be Forever Insecure — Lineaje analysis of 5,505 malicious skill-category records across 75 unique malicious skill URLs.