The risk has moved from the model to the ecosystem around it. A third-party skill can inherit an agent’s privileges, so a benign-looking add-on can become the place where credentials, files, or shell access are quietly turned against you.
CSO says frontier models like Claude Mythos and OpenAI GPT-5.5 are pushing vulnerability discovery toward industrial scale, and Unit 42 finds that most public agent skills diverge from their claims. The dangerous slice is smaller, but it includes multi-stage chains that can lead to credential theft, remote code execution, or silent data exfiltration without a novel exploit.
Benchmarking Fable, Opus, and GPT for vulnerability detection
We compare the performance of the latest models for vulnerability detection, using guided prompts and Claude Security directly. Semgrep Multimodal finds 3.5X more true positives, with AI alone being 37% more expensive than Semgrep’s approach.
Criminal AI-as-a-Service in 2026: How the Underground Market Is Operationalizing Cybercrime
While AI does not replace cybercriminals, it lowers friction, increases speed, and expands the range of actors able to perform tasks that previously required more time, skill, or external support. For today's organizations, the impact of AI-enabled cybercrime is both economic and operational.