AIR says its fake AI skill passed scanner checks by using a mutable external link, exposing a blind spot in agent skill ...
AIR says static scanning failed to detect a skill that redirected to a controlled domain and later altered its payload.
Picture this scenario: An Anthropic Skill scanner runs a full analysis of a Skill pulled from ClawHub or skills.sh. Its markdown instructions are clean, and no prompt injection is detected. No shell ...