conversational data analysis

Your scanner passed the skill. The test file didn't.

In a recent analysis, Gecko Security revealed a significant blind spot in the Anthropic Skill scanner: it fails to inspect bundled test files, which can execute malicious code with full access to the filesystem.

4 min readVentureBeat
Your scanner passed the skill. The test file didn't.

When security researchers at Gecko Security demonstrated that Anthropic Skill scanners passed every published check while malicious code rode in on an overlooked test file, it exposed something the ecosystem should have confronted much earlier. The scanners were solving the right problem with the wrong scope. As we explored after Claude Code, Copilot and Codex all got hacked. Every attacker went for the credential, not the model, attackers consistently target the layer of access that defenders forget to watch. That pattern is playing out again here, and the implications extend well beyond Anthropic Skills alone. For anyone following the supply-chain security conversation, this echoes the finding from One command turns any open-source repo into an AI agent backdoor, where researchers proved that no existing scanner had a detection category for a trivially simple backdoor vector.

The core issue is structural. Anthropic Skill scanners inspect SKILL.md and agent-invoked scripts, which is necessary and valuable work. Snyk's ToxicSkills audit found seventy-six confirmed malicious payloads across nearly four thousand Skills, and SkillScan's analysis of over thirty-one thousand Skills revealed that more than a quarter contained at least one vulnerability. These scanners earn their keep. But none of them examine bundled test files, build configurations, or CI scripts that land alongside the Skill definition on disk. Gecko proved that a malicious test file executes through standard runners like Jest and Vitest with full access to environment variables, SSH keys, and cloud credentials, all without ever invoking the agent. The attacker does not need to fool the AI. They simply need the developer to run tests, which happens automatically in most CI pipelines and IDEs on save.

What makes this vector particularly concerning is how naturally it propagates. The .agents directory is designed to be committed and shared across teams. GitHub's default gitignore templates do not exclude it. Once a malicious test file enters the repository, every developer who clones and runs tests executes the payload. Every CI pipeline on every branch inherits it. And because the scanner reported green, no one has reason to investigate. The trust-on-install model that plagued the early npm ecosystem has found a new home in the Skills marketplace, except this time the ecosystem lacks the decade of hard lessons that forced package registries to build security infrastructure.

The good news is that the fix is immediate and does not require replacing any tools. Three concrete steps can close the gap today. First, add the .agents directory to your test runner's ignore list. One line in jest.config.js or vitest.config.ts prevents the runner from discovering files inside installed Skill directories. Second, add a CI gate that flags any test, spec, or config files inside .agents before merge. Third, pin Skill sources to specific commit hashes rather than pulling the latest version, converting a trust-on-first-use model into a verify-on-every-change model. The OWASP Agentic Skills Top 10 already recommends this approach.

The harder question is what this means for the broader ecosystem of agent security tooling. If scanners continue to measure only the surfaces they already cover, the gap between documented protection and actual exposure will keep widening. Security teams evaluating Skill scanning vendors should ask a pointed question: which files and directories do you actually analyze, and what do you explicitly skip? The answer to that question defines the boundary between real security and reassuring theater. As agent identity frameworks multiply and enterprise adoption accelerates, the test-file vector is a preview of the kinds of blind spots that emerge whenever defenders optimize for the threat they expect instead of the attack surface that actually exists.

From VentureBeat

Picture this scenario: An Anthropic Skill scanner runs a full analysis of a Skill pulled from ClawHub or skills.sh. Its markdown instructions are clean, and no prompt injection is detected. No shell commands are hiding in the SKILL.md. Green across the board.

Read the original at VentureBeat