Static pre-install checks are a weak gate for AI agent skills. Attackers can keep tweaking a malicious skill and re-testing it until one version slips through, so “scan before install” does not separate safe skills from bad ones as well as teams assume.
Trail of Bits says it bypassed ClawHub’s malicious skill detector, Cisco’s agent skill scanner, and the three scanners built into skills.sh. The bypasses used public malicious skills and came quickly, which shows that scanner output can become feedback for attackers and that public skill marketplaces stay exposed to the same trust gap across Claude, OpenAI, Cisco, and skills.sh-style deployments.