Agent skills, the reusable instruction bundles agents autonomously load and execute, are now a documented attack surface. OWASP released the Agentic Skills Top 10 framework on August 17 to address ten critical risks in this emerging domain.
The problem is immediate. The ClawHavoc campaign distributed over 1,100 malicious skills in January, and a USENIX study found 157 malicious skills among nearly 100,000 analyzed. OpenClaw, Claude Code, Cursor, and other platforms now face active skill-based attacks.
Two risks are rated critical: malicious skills and supply chain compromise. A malicious skill executes inside an agent sandbox and can exfiltrate data, escalate privilege, or bridge trust boundaries. Supply chain compromise means attackers weaponize skills at source and distribute them to unsuspecting users.
The framework maps to AISVS and NIST, filling a gap between LLM security and tool-layer protections. But v1.0 is brand new, and platform adoption remains unclear. Whether platforms actually implement these controls is the open question.
Sources: OWASP Agentic Skills Top 10 • OWASP Publishes Agentic Skills Top 10 v1.0
Coverage: OWASP Flags Top AI Skill Risks in New Security Blueprint
Related on this blog: [AUTO] Hidden Ads Target AI Models at Publisher Level • [AUTO] AI Agents as Supply-Chain Attack Surface • [AUTO] Paperclip’s Real Problem: When Configuration Is Code