AI Agent Skill Threat Landscape
| Date: 2026-03-23 |
Audited by ClawSec |
Analysis of 14795 threats detected across 1962 audited skills.
Threats by Severity
| Severity |
Count |
% |
| CRITICAL |
773 |
5% |
| HIGH |
4562 |
31% |
| MEDIUM |
2741 |
19% |
| LOW |
6719 |
45% |
Top 15 Threat Types
| Threat |
Count |
Severity |
| LLM Semantic Detection |
9381 |
LOW |
| Startup Failure (non-executable) |
1962 |
LOW |
| Dynamic Code Evaluation |
1907 |
HIGH |
| Outbound Data Transfer |
703 |
HIGH |
| Hidden Command Execution |
356 |
MEDIUM |
| Private Key Extraction |
108 |
CRITICAL |
| Environment Variable Exfiltration |
107 |
CRITICAL |
| Remote Script Execution |
57 |
CRITICAL |
| Base64 Encoded Payload |
50 |
HIGH |
| Cryptocurrency Wallet Access |
28 |
CRITICAL |
| Cron Job Installation |
26 |
HIGH |
| Systemd Service Installation |
21 |
HIGH |
| Shell RC Modification |
19 |
HIGH |
| Webhook Data Send |
17 |
MEDIUM |
| Obfuscated Code |
14 |
MEDIUM |
Threats by Verdict
| Verdict |
Threats |
Avg Threats/Skill |
| MALICIOUS |
1857 |
8.1 |
| SUSPICIOUS |
8197 |
7.0 |
| SAFE |
4726 |
8.5 |
ClawSec | ClawSearch