NewsSnyk ToxicSkills 36 Percent ClawHub Skills Prompt InjectionSnyk Blog·high signalXBlueskyLinkedInCopy linkSnyk audit found 36% of ClawHub skills contain prompt injection, 1467 malicious payloads, supply chain compromisedSourceSource pageSnyk Blog↳ Follow the threadStack layer / Threat patternAlibaba's open-code-review shipped v1.12.1 today and claims 4.7x the precision of Claude Code at a fourteenth of the tokensGitHub TrendingStack layer / Threat patternSureForge encodes a research-plan-verify-review gate sequence as a plain-text agent skillGitHubStack layer / Threat patternSnyk put its agent-skill scanner behind a free web page called Skill InspectorSnyk LabsPolicy dependency / Threat patternAn audit of a production agent pipeline found a reported p99 latency of 2,147,483,647 ms, the signed 32-bit maximum, from a lifecycle clamparXiv 2609.12017Stack layer / Threat patternA Malicious Super-App Can Silently Own Every Mini-App Inside It, and Russia's MAX Demonstrates the Full SetarXiv 2609.11814Stack layer / Threat patternGemini CLI ships an external-context processor to stop indirect prompt injection through build filesGitHubStack layer / Threat pattern705 skill versions every ClawHub scanner rated clean still instruct an action banned by CIS Control 2.7, and 34.7% of a live agent's commands carried a consequence the skill doc never mentionedarXiv 2609.12001Policy dependency / Stack layerRIPPLE: an edit confined to one prompt-policy segment changes downstream behavior, so replay candidate edits after previously accepted ones before persistingarXiv 2609.12127