Tech Startup News | Tech Scoop Canada
No Result
View All Result
Subscribe
Tech Startup News | Tech Scoop Canada
No Result
View All Result
Tech Startup News | Tech Scoop Canada
No Result
View All Result

Anthropic Skill Scanners Pass All Checks Despite Malicious Code in Test File

TSC Desk by TSC Desk
May 7, 2026
in Security
Reading Time: 2 mins read
0 0
0
Anthropic Skill Scanners Pass All Checks Despite Malicious Code in Test File
Share

Anthropic Skill Scanners Miss Malicious Code in Test Files

Anthropic’s Skill scanners, designed to ensure security in AI agent skills, have been found lacking. Gecko Security uncovered a vulnerability where malicious code can sneak into a system via overlooked test files, bypassing the scanner’s scrutiny. This revelation is a stark reminder of the blind spots in current security practices and poses significant risks for developers and companies relying on open-source skill marketplaces.

### Understanding the Anthropic Skill Scanners

Related Posts

ShinyHunters Allegedly Breaches Data of 8,800 Schools Using Instructure Canvas

ShinyHunters Allegedly Breaches Data of 8,800 Schools Using Instructure Canvas

May 7, 2026
Mozilla Reports 271 Vulnerabilities Discovered by Mythos with Minimal False Positives

Mozilla Reports 271 Vulnerabilities Discovered by Mythos with Minimal False Positives

May 7, 2026
Hackers Target Schools, Deface Login Pages Following Instructure Breach Claims

Hackers Target Schools, Deface Login Pages Following Instructure Breach Claims

May 7, 2026
Hackers Target Victims Already Compromised by Previous Cyber Attacks

Hackers Target Victims Already Compromised by Previous Cyber Attacks

May 7, 2026

Anthropic Skill scanners are intended to detect malicious code in AI agent skills sourced from platforms like ClawHub and skills.sh. These scanners focus on scrutinizing markdown instructions, prompt injections, and shell commands within the core skill files. However, they fail to examine adjacent test files, such as .test.ts files, which fall outside the agent execution surface. Despite not being part of the execution, these files can still run via test runners like Jest and Vitest, gaining unauthorized access to sensitive information. The oversight highlights a critical gap in the security measures meant to protect systems from malicious skill injections.

### Competitive Context and Security Audits

The security landscape for AI agent skills has been under scrutiny with multiple audits exposing vulnerabilities. A SkillScan academic study revealed that 26.1% of the 31,132 Anthropic Skills analyzed contained vulnerabilities. Snyk’s ToxicSkills audit further corroborated these findings, identifying critical-level security issues in 13.4% of the skills from ClawHub and skills.sh. Despite these efforts, Gecko Security’s discovery suggests that current audits and tools, including Cisco’s AI Agent Security Scanner, are not comprehensive enough. They miss critical aspects like test files that can harbor malicious code and exploit trust-on-install practices.

### Implications for Founders, Engineers, and the Industry

This development poses significant implications for founders, engineers, and the broader industry. For developers, the oversight in Anthropic’s Skill scanner emphasizes the need for more robust security practices that extend beyond standard scanning protocols. Engineers must now consider additional layers of security checks, particularly for test files, to safeguard against unauthorized access and data breaches. For startups and companies, this revelation underscores the importance of scrutinizing the security measures of third-party tools and the need for ongoing vigilance in integrating AI skills from open-source platforms.

More broadly, this incident serves as a call to action for the industry to reevaluate security frameworks and ensure they evolve in tandem with new attack vectors. It highlights the necessity for a holistic approach to security that encompasses all aspects of code execution and file management.

### What Happens Next

Moving forward, the industry must address these vulnerabilities by expanding the scope of security audits and enhancing tool capabilities to include test files in their scans. For developers and founders, this means prioritizing security from the ground up, ensuring that all potential entry points are fortified against exploitation. Investors and stakeholders should also push for transparency and accountability in security practices to protect their interests and maintain trust in AI technologies.

Tweet
TSC Desk

TSC Desk

The TSC News Desk is the core of Tech Scoop Canada — a focused editorial team dedicated to covering the most important stories in Canada’s technology and startup ecosystem. Our writers, editors, and analysts work with accuracy and clarity to bring readers reliable, timely, and meaningful coverage. From Canadian startup funding rounds to policy developments shaping innovation, the TSC News Desk tracks the companies, founders, and technologies moving the country forward. With a commitment to journalistic integrity and a deep understanding of Canada’s tech landscape, the team ensures readers stay informed and ahead of the curve. TSC News Desk is where Canadian innovation meets trustworthy reporting.

Related Posts

ShinyHunters Allegedly Breaches Data of 8,800 Schools Using Instructure Canvas
Security

ShinyHunters Allegedly Breaches Data of 8,800 Schools Using Instructure Canvas

May 7, 2026

ShinyHunters, a cybercriminal group with a track record of high-profile data breaches, has reportedly...

Mozilla Reports 271 Vulnerabilities Discovered by Mythos with Minimal False Positives
Security

Mozilla Reports 271 Vulnerabilities Discovered by Mythos with Minimal False Positives

May 7, 2026

Mozilla has announced that its collaboration with cybersecurity firm Mythos has identified 271 vulnerabilities...

Hackers Target Schools, Deface Login Pages Following Instructure Breach Claims
Security

Hackers Target Schools, Deface Login Pages Following Instructure Breach Claims

May 7, 2026

Cybercrime Group ShinyHunters Strikes Instructure Again, Defacing School Login Pages In a new wave...

Hackers Target Victims Already Compromised by Previous Cyber Attacks
Security

Hackers Target Victims Already Compromised by Previous Cyber Attacks

May 7, 2026

A new breed of digital vigilantes is emerging in the cybercrime landscape. An unidentified...

  • Trending
  • Comments
  • Latest
PlayStation Portal Gains Traction After Initial Hesitation

PlayStation Portal Gains Traction After Initial Hesitation

March 14, 2026
Public Mobile Increases Data to Compete with Freedom Plans

Public Mobile Increases Data to Compete with Freedom Plans

December 16, 2025
Autoresearch Launches Tool for AI Experiment Automation

Autoresearch Launches Tool for AI Experiment Automation

March 14, 2026
Trump Mobile’s “Made in USA” Phones Appear to Be Old iPhones and Samsungs, Raising Serious Concerns

Trump Mobile’s “Made in USA” Phones Appear to Be Old iPhones and Samsungs, Raising Serious Concerns

December 8, 2025
Health Canada Recalls Thousands of Wireless Earbuds Over Fire Risk

Health Canada Recalls Thousands of Wireless Earbuds Over Fire Risk

0
Finofo Raises Funds to Innovate Forex with Automation

Finofo Raises Funds to Innovate Forex with Automation

0
BC Funds Local Tech Testing with 0K Grants

BC Funds Local Tech Testing with $500K Grants

0
Avatar: Frontiers of Pandora Launches New Chapter

Avatar: Frontiers of Pandora Launches New Chapter

0
Breaking News: Global Canvas Hack Targets Universities, Including Canada’s Top Two Institutions

Breaking News: Global Canvas Hack Targets Universities, Including Canada’s Top Two Institutions

May 7, 2026
Anthropic Unveils “Dreaming” System for AI Agents to Learn from Mistakes

Anthropic Unveils “Dreaming” System for AI Agents to Learn from Mistakes

May 7, 2026
Ramp Eyes B Valuation Just Six Months After B Milestone

Ramp Eyes $40B Valuation Just Six Months After $32B Milestone

May 7, 2026
OpenAI Unveils Advanced Voice Intelligence Features in API Update

OpenAI Unveils Advanced Voice Intelligence Features in API Update

May 7, 2026
Tech Scoop Canada

© 2026 Tech Scoop Canada

Navigate Site

  • Advertise With Us
  • About Us
  • News

Follow Us

Welcome Back!

Login to your account below

Forgotten Password? Sign Up

Create New Account!

Fill the forms below to register

All fields are required. Log In

Retrieve your password

Please enter your username or email address to reset your password.

Log In
No Result
View All Result
  • Funding
  • Hiring
  • Advertise With Us
  • About Us

© 2026 Tech Scoop Canada