
Agentic skills can make AI agents more capable and consistent—but they can also introduce serious security risks. This episode explains how skills work, why malicious skills rank as a leading OWASP concern, and how seemingly harmless Markdown instructions can enable credential theft, remote payload delivery, and manipulated recommendations. Real-world examples illustrate how malicious skills can evade scanners and exploit trusted marketplaces. The episode concludes with practical safeguards, including reviewing skill files, watching for external instructions and prompt injection, pinning versions, limiting permissions, and running agents inside isolated environments.Links:OWASP Agentic Skills Top 10Malicious AI Agent Skill Bypasses Security Scans and Seizes Full Control of Over 26,000 Agents(00:00) - Agentic Skills and the OWASP Top 10 (00:23) - Podcast Sponsors: BHIS and Antisyphon Training (01:29) - What Is an Agentic Skill? (03:13) - Skill Marketplaces and Widespread Adoption (03:46) - Why Malicious Skills Are the #1 Risk (05:50) - Remote Payloads and External Instructions (07:00) - Malicious Skill Takes Control of 26,000 Agents (08:09) - Money Radar and Manipulated Recommendations (09:20) - How to Evaluate and Use Skills Safely (11:08) - Closing Thoughts Click here to watch this episode on YouTube. Creators & Guests Brian Fehrman - Host Brought to you by:Black Hills Information Security https://www.blackhillsinfosec.com☯️ Introducing BHIS Fusion Penetration Testinghttps://www.blackhillsinfosec.com/fusion-penetration-testing/Antisyphon Traininghttps://www.antisyphontraining.com/Active Countermeasureshttps://www.activecountermeasures.comWild West Hackin Festhttps://wildwesthackinfest.com🔗 Register for FREE Infosec Webcasts, Anti-casts & Summitshttps://poweredbybhis.com Click here to view the episode transcript.
Podzilla Summary coming soon
Sign up to get notified when the full AI-powered summary is ready.
Free forever for up to 3 podcasts. No credit card required.

Data Becomes Code | Episode 68

Who is Responsible for an AI-Caused Breach? | Episode 67

Banning Open Weight Models | Episode 66

OpenAI / Hugging Face Breach Walkthrough | Episode 65
Free AI-powered recaps of AI Security Ops and your other favorite podcasts, delivered to your inbox.
Free forever for up to 3 podcasts. No credit card required.