generative AI for data analysis

Explore how a single command can turn any open-source repo into an AI agent backdoor.

Researchers at the University of Hong Kong have unveiled CLI-Anything, a groundbreaking tool that transforms any open-source repository into an AI agent interface with a single command.

4 min readVentureBeat
Explore how a single command can turn any open-source repo into an AI agent backdoor.

# Our Take: The Agent Integration Layer Is the Security Gap You Didn't Know to Look For

The security industry has spent decades refining its ability to see two things: code and dependencies. SAST tools scan source files for vulnerabilities. SCA tools check package versions against known CVEs. Together, they form the backbone of software supply-chain security, and for good reason—they work well within their defined boundaries. But the AI agent revolution has introduced a third layer that neither category was built to see, and the first major proof case is already live. CLI-Anything, a tool that generates command-line interfaces for AI coding agents, has attracted more than 30,000 GitHub stars in just two months. It is genuinely useful. It is also the catalyst for a structural vulnerability that the security industry is only beginning to name.

The gap is not a single vendor's failure. It is architectural. Agent bridge tools like CLI-Anything, MCP connectors, Cursor rules files, and Claude Code skills operate on what researchers now call the agent integration layer—configuration files, skill definitions, and natural-language instruction sets that tell an AI agent what it can do and how to operate. None of it looks like executable code. All of it executes like code. When a poisoned SKILL.md file lands in a repository, it sails through code review because no human approves markdown as dangerous. It never appears in an SBOM because SCA tools do not inventory agent skills. And it does not trigger a CVE because the category did not exist eighteen months ago. The attack community has already noticed. Related coverage from our publication has documented how Anthropic Skill scanners passed every check. The malicious code rode in on a test file., illustrating how even dedicated scanning tools struggle with this new attack surface.

The evidence is not theoretical. Snyk's ToxicSkills audit found that 13.4% of agent skills from public marketplaces contained critical security issues. The ClawHavoc campaign identified more than 1,000 malicious skills delivering stealer malware through professionally documented packages that matched what developers were actively searching for. In one documented attack, a crafted GitHub issue title triggered an AI triage bot, exfiltrated a GitHub token, and enabled attackers to publish a compromised npm dependency that installed an agent on roughly 4,000 developer machines for eight hours. No human approved any of it. The kill chain works because every link operates through channels the monitoring stack considers normal—approved API calls from authorized processes, executing with the developer's own credentials. This is not a vulnerability that escalates privileges. It inherits them.

What makes this moment significant is the timing. Cisco and Snyk shipped the first purpose-built tools for this layer in April 2026—Cisco's Skill Scanner and Snyk's mcp-scan represent the industry's acknowledgment that the category exists. But tooling is only the first step. The harder work is organizational: inventorying every agent bridge tool in the environment, auditing skill sources the way package registries get audited, restricting agent execution privileges so that a compromised skill cannot automatically access everything the developer can access, and assigning ownership for the gap between layers. As Merritt Baer, CSO of Enkrypt AI, observed, this feels very similar to early container security—but there is no build pipeline, no compilation barrier. Just content. The window between the emergence of a new attack surface and the deployment of defenses to match it is closing. Security leaders who have not begun inventorying their agent integration layer are already behind the curve, and the 33,000 developers who have already starred CLI-Anything are signaling exactly where software development is heading.

From VentureBeat

Just two months ago, researchers at the Data Intelligence Lab at the University of Hong Kong introduced CLI-Anything, a new state-of-the-art tool that analyzes any repo’s source code and generates a structured command line interface (CLI) that AI coding agents can operate with a single command.

Claude Code, Codex, OpenClaw, Cursor, and GitHub Copilot CLI are all supported, and since its launch in March, CLI‑Anything has climbed to more than 30,000 GitHub stars.

Read the original at VentureBeat