Toxic Flows: When Your Agent Skill Becomes a Supply Chain Attack (June 18th)
Thursday, June 18th, 2026: 11:00 AM to 12:00 PM
When a developer installs an AI agent skill, they are making a trust decision they almost certainly do not know they are making. Snyk’s ToxicSkills research into 3,000+ skills from ClawHub and skills.sh found that 36% contain security flaws and 13% contain critical issues, including credential theft, backdoor installation, and active prompt injection payloads.
more →








