When you install an AI skill, you are adding instructions that run inside a system with access to your files, credentials, conversations, and organisational data.
NVIDIA research across 42,447 real-world skills found that 26.1% contain vulnerabilities and 5.2% show likely malicious intent. One in four is broken. One in twenty is actively trying to cause harm.
What a malicious skill can do
A skill can exploit prompt injection, data exfiltration, privilege escalation, supply-chain attacks, memory poisoning, context-window stuffing, MCP tool poisoning, and other patterns. In plain language, it may try to steal credentials, persist instructions, override safety constraints, or modify behaviour without authorisation.
Scan before you install
NVIDIA SkillSpector is an open-source scanner for AI agent skills. It uses static analysis, Python AST checks, YARA signatures, CVE lookups, and optional semantic evaluation. It covers 65 vulnerability patterns across 16 categories and produces terminal, JSON, Markdown, or SARIF output.
The practical habit is simple: before installing any third-party skill, scan it. If you build skills, scan your own before sharing them. Vulnerabilities can be unintentional, and the patterns that make a skill exploitable are not always obvious to its author.
A skill is software. It runs inside your AI system, with your access, on your data. Check it first.
This is part of the Parenting Your AI series, a practitioner's guide to building AI skills that are safe, effective, and worth trusting. Written from inside enterprise AI systems by someone who has spent years diagnosing what goes wrong when AI meets real work at scale.
Read the full series at KnowledgeManagement.ie