NewsToxicSkills: 36% of ClawHub Skills Contain Malicious ComponentsUC Berkeley·high signalXBlueskyLinkedInCopy linkUC Berkeley study finds 36% of popular AI agent skills on ClawHub marketplace contain data exfiltration, prompt injection, or privilege escalation.SourceSource pageUC Berkeley↳ Follow the threadPolicy dependency / Stack layerPython's Import Statement Is an Execution Boundary: 90% of Initialization-Activated Advisory Vulnerabilities Are High or CriticalarXiv 2609.14791Stack layer / Threat patternUnlearning Methods That Pass TOFU and MUSE Still Leak the Secret on 22-86% of Queries Once the Model Is an AgentarXiv 2609.12808Policy dependency / Threat patternA Fine-Tuned RoBERTa-Large Permission Gate Matches Claude Haiku 4.5 at Deciding What an Agent May ToucharXiv 2609.15422Threat pattern / Update threadAdversarial Issue Descriptions Make Repair Agents Ship Correct-but-Insecure Patches in 51.7% of CasesarXiv 2609.15963Stack layer / ContrastRemoving the Tenant ID From an MCP Tool Schema Blocks Cross-Tenant Reads That a Validated Parameter Let Through 26 Times Out of 26arXiv 2609.14780Stack layer705 skill versions every ClawHub scanner rated clean still instruct an action banned by CIS Control 2.7, and 34.7% of a live agent's commands carried a consequence the skill doc never mentionedarXiv 2609.12001Policy dependency / Stack layerRIPPLE: an edit confined to one prompt-policy segment changes downstream behavior, so replay candidate edits after previously accepted ones before persistingarXiv 2609.12127Stack layer / Follow-up threadPlanting Benign-Sounding Reasoning in an Agent's Context Evades Chain-of-Thought Monitors 25-33% of the TimearXiv 2609.15989