{"type":"rich","version":"1.0","provider_name":"Transistor","provider_url":"https://transistor.fm","author_name":"AI Security Ops","title":"Agentic Skills | Episode 69","html":"<iframe width=\"100%\" height=\"180\" frameborder=\"no\" scrolling=\"no\" seamless src=\"https://share.transistor.fm/e/319c5014\"></iframe>","width":"100%","height":180,"duration":688,"description":"Agentic skills can make AI agents more capable and consistent—but they can also introduce serious security risks. This episode explains how skills work, why malicious skills rank as a leading OWASP concern, and how seemingly harmless Markdown instructions can enable credential theft, remote payload delivery, and manipulated recommendations. Real-world examples illustrate how malicious skills can evade scanners and exploit trusted marketplaces. The episode concludes with practical safeguards, including reviewing skill files, watching for external instructions and prompt injection, pinning versions, limiting permissions, and running agents inside isolated environments.\nLinks:\nOWASP Agentic Skills Top 10\nMalicious AI Agent Skill Bypasses Security Scans and Seizes Full Control of Over 26,000 Agents\n\nBrought to you by:\nBlack Hills Information Security \nhttps://www.blackhillsinfosec.com\n\n☯️ Introducing BHIS Fusion Penetration Testing\nhttps://www.blackhillsinfosec.com/fusion-penetration-testing/\nAntisyphon Training\nhttps://www.antisyphontraining.com/\n\nActive Countermeasures\nhttps://www.activecountermeasures.com\n\nWild West Hackin Fest\nhttps://wildwesthackinfest.com\n🔗 Register for FREE Infosec Webcasts, Anti-casts & Summits\nhttps://poweredbybhis.com","thumbnail_url":"https://img.transistorcdn.com/mN9_Xu9UJwoaajIvIvLd-Yygv-Vh_nJwEDItjPY09kA/rs:fill:0:0:1/w:400/h:400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS8zYjBm/MzE1MWI2YmE4ZGJh/MDQ3MmJkMTkxZGNl/MjBjNS5wbmc.webp","thumbnail_width":300,"thumbnail_height":300}