Zenity Labs — malicious AI-agent skills research & AI Total launch (Black Hat USA, August 2026)
Tag: S-2026-08-06-zenity-ai-total Type: article (vendor research press release, primary, fetched in full) Author(s): Zenity Labs Date of source: 2026-08-06 (article dateline, Black Hat USA; page metadata says published 2026-08-03 — discrepancy preserved in the raw stub) Date ingested: 2026-08-14 Authority weight: medium — primary vendor research presented at Black Hat USA 2026, but a research-marketing pairing (the findings launch the vendor’s own tool); findings not independently replicated in anything read here; full research report not read. Raw file: /_raw_sources/S-2026-08-06-zenity-ai-total.md
What it claims
Zenity Labs disclosed research (Black Hat USA, dateline 6 Aug 2026) uncovering dozens of malicious AI-agent “skills” in public registries, designed to deliver malware, manipulate agent configurations, exfiltrate data and execute attacker-controlled instructions. Claimed findings: more than 30% of dangerous identified skills abuse Claude Code and “OpenClaw” as malware droppers; one skill re-installs itself via system-prompt manipulation if deleted; another covertly replaces the agent’s own skill-creator; one malicious skill amassed 250,000+ installs undetected for months and reached the top 150 of a popular registry; a typosquatting infrastructure of hundreds of reserved package names was found. The release frames the agent supply chain as extending “beyond traditional code dependencies to include skills, tools, MCP servers, packages, files and any content on the internet”. Alongside the research, Zenity launched AI Total (aitotal.io) — a free threat-intelligence service built on an “Agent Detonation Chamber”: skills are executed by a live agent in a contained sandbox seeded with bait credentials/files, and judged on observed runtime behaviour (domains reached, packages pulled, files touched, actions taken) rather than static code/instruction analysis, which the release argues structurally misses runtime-emergent maliciousness.
Notable quotes
“For AI agents, the supply chain extends beyond traditional code dependencies to include skills, tools, MCP servers, packages, files and any content on the internet.” (release body)
“What a skill actually does, compared to what it claims to do, becomes the verdict.” (release body, on the Agent Detonation Chamber)
What’s speculative vs. asserted
- Asserted by the source: all research findings (counts, percentages, the 250k-install skill, typosquatting infrastructure) — vendor research claims, presented publicly at Black Hat but not independently replicated here.
- Argued, not established: that static analysis structurally misses these threats (plausible, consistent with malware-analysis practice, but the vendor’s own case for its dynamic-analysis product).
- Not claimed: any FS-specific incident; any regulatory mapping; any named victim organisation.
Topics this feeds
- AI Governance Platforms — adds the AI supply chain (agent skills/tools/MCP servers) as a distinct attack surface and the dynamic-behavioural-testing locus to the agentic-assurance architecture.
- Zenity — company page.
Open questions raised
- Should third-party agent skills/tools/MCP servers be treated as ICT third-party assets under DORA and inventoried/tested accordingly — and does static pre-approval of agent components now constitute a demonstrated control gap? [inference from this vault]
- Is dynamic “detonation” testing of agent components implementable as a repeatable control with evidence a second/third line could review — and who operates it (the free vendor service vs in-house)?