AST09 & AST10: Governance and Cross-Platform Reuse

The finale of our OWASP Agentic Skills Top 10 series. AST09: one-line skill installs that no inventory, IAM system, or SOC ever sees — 800+ malicious skills circulating, 83% of organizations deploying agentic AI, 29% ready. AST10: porting skills across platforms silently drops manifests, permissions, and risk tiers. With the Bilateral Receipt Pattern, EU AI Act Article 12, and the Universal Skill Format proposal.

Continue ReadingAST09 & AST10: Governance and Cross-Platform Reuse
Read more about the article AST07 & AST08: Update Drift and Weak Scanning
OWASP Agentic Skills Top 10 series cover (cover_p7.png)

AST07 & AST08: Update Drift and Weak Scanning

The two post-deployment risks in the OWASP Agentic Skills Top 10: AST07 malicious updates riding channels with no signatures, pinning or freeze mode (40,000 exposed instances in 24 hours), and AST08 scanners that structurally lag base64, zero-width, pure-natural-language and .pyc evasion. Digest pinning, PASS/FAIL/INCOMPLETE pipelines, and Unicode strip ranges — dissected.

Continue ReadingAST07 & AST08: Update Drift and Weak Scanning
Read more about the article The Pipeline Is the Attack: AST02 Skill Supply Chain Compromise, Explained
OWASP Agentic Skills Top 10 series cover (cover_p3.png)

The Pipeline Is the Attack: AST02 Skill Supply Chain Compromise, Explained

AST02 of the OWASP Agentic Skills Top 10 maps attacks on the skill distribution layer: registry flooding, dependency confusion, config files that execute on clone (CVE-2025-59536, CVE-2026-21852), and maintainer takeover. With Trail of Bits' evidence that every marketplace scanner can be bypassed.

Continue ReadingThe Pipeline Is the Attack: AST02 Skill Supply Chain Compromise, Explained
Read more about the article AST01: Malicious Agent Skills (ClawHavoc Case Study)
OWASP Agentic Skills Top 10 series cover (cover_p2.png)

AST01: Malicious Agent Skills (ClawHavoc Case Study)

AST01 of the OWASP Agentic Skills Top 10 dissected: how ClawHavoc shipped 1,184 malicious skills from 12 accounts, why five of ClawHub's top seven downloads were malware, and how three lines of markdown exfiltrated SSH keys - with the full attack playbook and controls.

Continue ReadingAST01: Malicious Agent Skills (ClawHavoc Case Study)
Read more about the article Agent Skills Are the New npm: OWASP Agentic Skills Top 10 Explained
OWASP Agentic Skills Top 10 series cover (cover_p1.png)

Agent Skills Are the New npm: OWASP Agentic Skills Top 10 Explained

The OWASP Agentic Skills Top 10 maps the 10 risks of the AI-agent skill ecosystem - malicious skills, supply chain compromise, over-privileged manifests, metadata attacks, weak isolation, update drift, scanning gaps, governance failures and cross-platform reuse - with real 2026 evidence.

Continue ReadingAgent Skills Are the New npm: OWASP Agentic Skills Top 10 Explained
Read more about the article Marquis Data Breach: One SonicWall Firewall, 74 Banks, 672,075 Identities
Marquis breach anatomy – one cracked firewall rippling across 74 banks

Marquis Data Breach: One SonicWall Firewall, 74 Banks, 672,075 Identities

Attackers entered Texas fintech Marquis through a SonicWall firewall and reached data for 700+ client banks - 672,075 identities, 74 institutions disrupted. The supply-chain anatomy and five break-points.

Continue ReadingMarquis Data Breach: One SonicWall Firewall, 74 Banks, 672,075 Identities

Bleeding Llama: The Ollama CVE That Leaked AI Memory

Two AI security incidents in 48 hours: Bleeding Llama (CVE-2026-7482, CVSS 9.1) leaks full process memory from 300K+ exposed Ollama servers via malicious GGUF files, while a fake OpenAI Privacy Filter on Hugging Face hit #1 trending and delivered a Rust infostealer to 244K+ victims. Verification and patching playbook inside.

Continue ReadingBleeding Llama: The Ollama CVE That Leaked AI Memory