Researchers Show AI Coding Agent 'Skills' Can Hide Malware From Every Scanner Tested
A Hong Kong team's packing trick beat static scanners more than 90% of the time. Their own runtime checker caught most of it.

Key points
- Researchers at the Hong Kong University of Science and Technology showed that malicious add-on "skills" for AI coding agents can slip past every scanner they tested.
- Their strongest evasion technique, SkillCloak, worked more than 90% of the time against static scanning tools.
- The same team built a runtime checker that spots most of the hidden malware once it actually runs.
- Fresh questions follow about how software companies vet third-party plug-ins for AI assistants used by developers.
AI coding agents are helpers that write and edit code for programmers, essentially a fast junior developer living inside a software project. To extend their usefulness, companies let outsiders publish "skills", small add-ons that bolt new abilities onto the agent, much like extensions bolt onto a browser.
That model has an obvious flaw. If anyone can publish a skill, someone will publish a bad one.
So the industry built scanners to check skills before they run, looking through the code for known signs of trouble. A new study says those scanners are easy to fool.
Researchers at the Hong Kong University of Science and Technology, first reported by The Hacker News, tested a technique they call SkillCloak. It repackages a malicious skill so the harmful instructions only unpack at the moment the skill loads. The scanner, looking at the file on disk, sees something that appears harmless.
In their tests, SkillCloak cleared every scanner they tried more than 90% of the time. The malware still worked once the skill was live.
Why does this matter to people who don't write code?
Because the software your bank and your hospital depend on is increasingly built with help from these AI assistants. A poisoned skill inside a developer's tool can quietly steal source code or the credentials that open company servers. Customers feel the damage weeks later, in the form of a breach.
The underlying trick isn't new. Malware authors have hidden their code inside self-extracting packages for decades to duck antivirus checks. What's new is that the same approach works against tools built specifically to police AI skill marketplaces. We covered a related angle on 8 June 2026 when Microsoft added a two-hour quarantine window to VS Code extension auto-updates as a soft brake against exactly this kind of supply chain move.
The researchers didn't just point at the problem. They built a defensive tool that watches skills as they run and flags suspicious behaviour in real time. It catches most, though not all, of the packed malware their own attack produced.
That gap matters: runtime detection means the malware has already started executing on a developer's machine before the alarm rings. Static scanning was supposed to stop it at the door.
What should developers and companies do now?
Treat every third-party AI skill the way you'd treat a browser extension from an unknown publisher: with suspicion. Install only what you need, and prefer skills from vendors with a verifiable track record.
Security teams should accept that the pre-publication scan isn't the last line of defence. Watch what skills actually do once loaded: which files they read, which servers they contact, which credentials they touch.
This paper arrives as the AI coding attack surface keeps widening. Since we started covering it in June, prompt injection hidden in a repository was enough to turn Claude Code against the developer running it, and two Cursor vulnerabilities could let an attacker silently take control of a machine with no click required. SkillCloak is a third vector in the same campaign against developer trust.
The front door of the AI skill ecosystem can be walked past. That's the finding, and it's the one to watch.



