Vibe CodingToxicSkills: 36% of Agent Skills Have Security FlawsSnyk Blog·high signalXBlueskyLinkedInCopy linkSnyk finds 1,467/3,984 skills have flaws, 534 critical, 76 malicious payloadsSourceSource pageSnyk Blog↳ Follow the threadPolicy dependency / Stack layerHierarchical Ransomware Agents Escalate to Dynamic and Memory Analysis Only on Specialist DisagreementarXiv 2609.04820Threat pattern / Contrast26-Condition Study Finds Doing Nothing Beats TDD, Formal Methods and Published Skills for Agent CorrectnessDan LuuStack layer / Threat pattern16% of 3,171 public agent-harness setups carry a confirmed security defect, and 3.8% ship a skill that pre-approves your shellarXivPolicy dependency / Stack layer83.3% of 281 open-source AI contribution policies permit AI code, but 67.3% demand a high level of human involvementarXivPolicy dependency / Stack layerNSA, CISA and FBI Name Six Chinese AI Firms in a Joint Advisory on Industrial-Scale DistillationCISAPolicy dependency / Stack layerMemSentry gates persistent memory writes on a signed security-state delta rather than on content classificationarXivStack layer / Threat patternHuman reviewers approve AI-generated code more often the longer they are exposed to it: 30.5% rising to 36.6%arXivStack layer / Threat patternA weaker agent recovered 80% of a stronger proprietary agent's capability gap from black-box execution differences alonearXiv 2609.07131