By NHI Mgmt Group Editorial TeamBased on Orca Security: “Skill Issues: How We Discovered Supply Chain Attack Vectors in an AI Agent Skills Marketplace” (May 5, 2026)

TL;DR: AI agent skill marketplaces can be weaponized through spoofed popularity signals, non-continuous scanning, silent overrides, and blind bulk updates, allowing malicious skills to reach users with persistent code execution, according to Orca Security. Treating skills as untrusted code is now a supply chain identity problem, not just a developer convenience issue.


At a glance

What this is: This analysis shows how AI agent skill marketplaces can be manipulated through spoofed trust signals, weak scanning cadence, and unsafe update mechanics to deliver malicious skills.

Why it matters: IAM, NHI, and agentic AI teams need to treat marketplace skills as governed supply chain artifacts because trust, installation, and update paths can become execution paths.


Context

AI agent skills are reusable prompt-based extensions that can shape what an agent does, what commands it can run, and how it behaves in a workflow. In a marketplace model, the security problem is not just whether the skill is useful, but whether the distribution, installation, and update path can be trusted.

Orca Security's analysis shows that the trust boundary for agent skills is weaker than many teams assume. Popularity signals, repository scanning, and bulk updates can all be manipulated, which means the identity and authorization model around agent-installed code matters as much as the code itself.


Key questions

Q: What breaks when AI agent skills can silently replace trusted ones?

A: Trust collapses when name matching is treated as identity. A silent replacement turns the skill label into a spoofable control, so the platform can present one source while executing another. Practitioners should require provenance checks, collision warnings, and reviewable diffs before any replacement is allowed.

Q: Why do delayed security scans create risk for AI agent marketplaces?

A: Because a clean scan at publish time does not protect against later repository changes. If the platform rescans only when a skill becomes popular, attackers get a window to ship benign code, pass audit, and then mutate the repository before the next verification cycle. Continuous revalidation closes that gap.

Q: What do security teams get wrong about bulk updates for agent skills?

A: They often assume an update command is a maintenance action, not an execution event. When one command refreshes every installed skill at once, a single malicious change can spread without per-skill review. Teams should treat update mechanics as part of the attack surface and control them accordingly.

Q: How should teams govern agent skills in supply chain security programmes?

A: They should govern skills like untrusted software artifacts with identity implications. That means tracking source, version, update path, and runtime authority together, because the agent inherits whatever the skill can instruct it to do. Supply chain controls and identity controls need to meet at installation time.


Technical breakdown

How AI agent skill marketplaces turn trust signals into attack surface

An agent skill marketplace does more than host files. It aggregates metadata, popularity signals, scan status, and installation workflows into one trust decision that users often treat as proof of safety. That creates a compound trust surface: if install counts can be inflated, scan results are stale, or a same-name package can silently replace another skill, the marketplace is no longer just a catalog. It becomes an execution channel. In agentic environments, the skill is not inert content. It can instruct the agent to run commands, fetch code, or change behaviour during execution.

Practical implication: Treat marketplace reputation as untrusted metadata and validate the source repository, package identity, and update path before installation.

Why non-continuous scanning leaves a malicious skill window open

The article describes scans that run at creation and again only when popularity thresholds are crossed. That means the platform can present a clean audit state while the underlying repository has already changed. The technical weakness is not scanning itself, but scan cadence and revalidation triggers. In software supply chain terms, the platform is missing continuous attestation of content integrity. Once the scan and the live repository drift apart, users are making trust decisions on stale evidence, which is enough time for a malicious skill to spread and execute.

Practical implication: Require continuous rescanning or change-triggered revalidation for skills, not one-time approval at publish time.

Why silent override and bulk update mechanics amplify agentic risk

When a new skill with the same name silently replaces an existing one, identity is being inferred from a label rather than a verified package boundary. Bulk update commands create a second problem: they refresh all installed skills together, so a benign skill can become malicious without a per-item review step. For agentic systems, that matters because the agent can execute the updated instructions immediately. The practical risk is not just code change. It is uncontrolled authority change inside a tool that users already trust to act on their behalf.

Practical implication: Pin versions, review diffs before update, and block same-name collisions unless identity and provenance are explicitly verified.


Threat narrative

Attacker objective: The attacker wants persistent code execution on agent-managed developer systems while preserving the appearance of legitimacy long enough for broad distribution.

  1. Entry begins when a user installs a skill from a marketplace that presents inflated popularity and clean-looking audit status.
  2. Credential or execution abuse follows when the skill's prompt content causes the agent to run embedded commands or install a second malicious skill.
  3. Impact occurs when the agent executes attacker-controlled code on end-user systems with persistent reach across update cycles.
  • reviewdog Action compromise 2025: A stolen maintainer token poisoned reviewdog/action-setup, leaking CI secrets including the tj-actions bot token used in the next attack.

Read and download The State of NHI & AI Agent Breach Report 2026, covering 200+ breaches impacting Non-Human Identities including AI Agents.


NHI Mgmt Group analysis

Marketplace reputation is not an access-control primitive: install counts, scan badges, and popular listings are metadata, not proof of trust. Orca Security's analysis shows that once those signals are easy to spoof, they stop functioning as identity evidence and start functioning as attacker camouflage. Practitioners should treat marketplace reputation as advisory context only.

AI agent skills are a software supply chain problem before they are a prompt problem: the dangerous part is the distribution model that lets executable instructions arrive through a trusted-looking channel. When a skill can embed shell commands, override existing entries, and refresh silently through bulk updates, the control plane is effectively a package manager for agent execution. Teams should govern skills as first-class artifacts.

Continuous verification, not one-time approval, is the missing control plane: the article's weakest point is the gap between creation-time scanning and later repository mutation. That gap turns approval into a snapshot rather than an ongoing trust decision. The implication is that identity governance for agent skills has to move from onboarding checks to lifecycle assurance.

Agent skills expose a new identity blast radius: a malicious skill does not just execute code, it inherits the agent's operational authority and user trust. That creates a broader blast radius than a normal download because the compromise is mediated through an identity-bearing runtime rather than a static file. Security programmes need to track what the agent can do after the skill is installed, not just whether the package was reviewed.

Abuse-resistant skill governance now belongs in NHI and agentic AI programmes: the same discipline used for service-account lifecycle, provenance, and offboarding now applies to skills that can be installed, replaced, and updated without strong identity checks. The named concept here is skill trust debt: the accumulated risk created when marketplace convenience outruns provenance, revocation, and change control. Practitioners should treat that debt as an operational exposure, not a theoretical concern.

From our research library:

What this signals

Skill trust debt: Marketplace convenience creates a growing gap between what the user sees and what the agent can execute. If identity governance does not follow the update path, a benign skill can become an execution vehicle long after the original approval decision.

Teams should expect supply chain controls to move closer to runtime authority, because the compromise path is no longer limited to source code review. In a major 2025 supply chain attack, 59% of compromised machines were CI/CD runners rather than personal workstations, according to the State of Secrets Sprawl 2026.

For agentic programmes, the operational question is no longer whether a skill was approved once. It is whether provenance, update control, and execution authority remain aligned throughout the skill's life.


For practitioners

  • Verify skill provenance before installation Inspect the source repository, name history, and rendered content before allowing an AI skill into an environment. Do not rely on install counts or marketplace badges as proof that the skill is safe.
  • Pin skill versions and review diffs Block blind bulk updates by requiring per-skill version pinning, visible diffs, and explicit review before changes reach agents that can execute commands.
  • Enforce collision warnings for same-name skills Alert operators when a new skill name matches an existing trusted skill from another repository. Treat same-name replacement as a provenance event, not a convenience feature.
  • Continuously rescan skill repositories Revalidate skill content whenever a repository changes, not only when it is created or crosses a popularity threshold. Stale audit state should never outlive the source content.

Key takeaways

  • AI agent skill marketplaces can turn popularity signals, scan cadence, and update mechanics into a practical compromise path.
  • The evidence in the article shows real code execution on end-user systems, not just theoretical prompt abuse.
  • Continuous verification, version pinning, and provenance checks are the controls most directly aligned to the failure mode.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Agentic AI Top 10, OWASP Non-Human Identity Top 10 and MITRE ATT&CK define the specific risk controls and attack patterns relevant to this term.

FrameworkControl / ReferenceRelevance
OWASP Agentic AI Top 10ASI04 — Agentic Supply Chain VulnerabilitiesThe article centers on malicious skills and marketplace distribution abuse.
ASI02 — Tool MisuseMalicious skills drive agents to execute untrusted commands and update flows.
ASI03 — Identity & Privilege AbuseThe attack abuses the authority the agent inherits from installed skills.
Recommendation — Assess skill marketplaces for supply chain injection paths and verify provenance before execution. Restrict agent tool execution to reviewed skills and block arbitrary command pathways. Constrain inherited agent privileges and review what installed skills can instruct the agent to do.
OWASP Non-Human Identity Top 10NHI-03 — Vulnerable Third-Party NHIThird-party marketplace skills act as externally supplied identities and code.
Recommendation — Treat third-party skills as untrusted dependencies and verify their provenance before use.
MITRE ATT&CKTA0006; TA0008 — Credential Access; Lateral MovementThe article shows how malicious skills can lead to code execution and downstream reach.
Recommendation — Map skill-driven execution paths to credential access and lateral movement techniques in detection rules.

Key terms

  • AI Agent Skill: A downloadable capability package that extends what an agent can do by adding tools, actions, or workflows. In practice, the skill becomes part of the agent's execution path and inherits the agent's permissions, so its risk is determined by both code behaviour and the identity context it runs in.
  • Skill trust debt: Skill trust debt is the accumulation of operational dependence on third-party instruction packages before verification, signing, and isolation controls exist. It grows when teams value convenience and speed over governance. The more skills a programme adopts without review, the more difficult it becomes to distinguish useful automation from embedded abuse.
  • Marketplace Provenance: Marketplace provenance is the origin trail for a plugin or extension, showing where it was installed from and how it entered the environment. It helps security teams judge trust, assess supply chain risk, and distinguish official sources from community or repository-based installs that may behave differently over time.
  • Runtime authority: Runtime authority is the permission an AI system has while it is actively deciding and acting, not just when it is approved. In governance terms, it is the point where access, tool use, and action scope become operational, which is why build-time review alone cannot prove safety.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are responsible for identity security strategy or NHI governance in your organisation, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 9, 2026.
Updated on October 10, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org