A skill is executable trust: discovery, installation and updates need the same controls as software packages.
Researchers are warning about malicious repositories presented as AI-agent skills, connectors or MCP servers. The attack works because an agent may be encouraged to discover and install a tool while the user focuses on the promised capability rather than the code and permissions behind it.
This makes the agent ecosystem look increasingly like a software supply chain. A skill can contain instructions, scripts, network access and credentials; popularity or a convincing description does not establish safety. Automated installation can shorten the distance between discovery and compromise to a single approval.
Safer systems need signed packages, pinned versions, permission manifests, reputation signals and sandboxed execution. Enterprises should maintain an approved catalog and record which agent installed what. The useful mental model is simple: adding a skill is not teaching the model a tip—it is extending a program with someone else’s code and authority.
This briefing summarizes reported facts and adds independent context. It does not reproduce the source article's wording or structure.