Join in on weekly podcasts that aim to illuminate how AI transforms cybersecurity—exploring emerging threats, tools, and trends—while equipping viewers with knowledge they can use practically (e.g., for secure coding or business risk mitigation).
Hey, everyone, and welcome to this week's episode of AI Security Ops. This episode, we're going to talk about five, the first five of the OWASP agentic skills top 10, which was released over the summer, if I am not mistaken. So we'll talk a little bit about these first five in this episode, and then in our next episode, we can talk about the second half of them. But before we get into that, let's talk about our sponsors, Black Hills Information Security. If you or your organization are in need of any computer security services, whether that's external testing, internal testing, assume compromise, social engineering, physical testing, wireless testing, hardware testing, I don't know, any kind of testing.
Brian Fehrman:Not... Last but not least, AI driven slash augmented pen testing or testing of your AI systems, check us out at blackhillsinfosec.com. Additionally, we have our training branch of Antisyphon Training, where many of our consultants take their knowledge from their tasks they're doing day in and day out, and they package it up in an easy to digest and affordable format so that you can hopefully learn something new, maybe level up in your current position, work towards that position that you've been wanting to get, or maybe you're just a hobbyist and you wanna learn something new at a very affordable price, extremely affordable when it comes to the trading these days. So check us out at antisyphontraining.com. So let's get into it.
Brian Fehrman:So again, these are
Derek Banks:Let's get down to it.
Brian Fehrman:Get down to it. Time to get down to business. And we need little, like, music, like, little, soundboard things that we can start using for these episodes, like the DJs have and Oh. Or we can, like, you know, like, you hit the button and it plays, like, a some kind of a like a sound or a little quip or whatever. Yeah.
Brian Fehrman:We'll get it. We'll get there one day. So, first one, their top one is malicious skills, which is, very broad. So the top 10 risk for Agentic skills is if it's one of them's malicious.
Derek Banks:Not not to be confused with the top 10 risks for Agentic AI as a whole, but just specifically for skills.
Brian Fehrman:For skills. Yep. Alright. So number one is malicious skills. So maybe first, before we dive into this for those who don't know, maybe we should talk a little bit about what are skills.
Derek Banks:Yeah. So skills are, typically, for an agentic coding harness, such as Claude code or OpenCode or Hermes or or Codex, and there's probably a bunch of other ones out there now. Seems like everybody and their brother has some kind of harness coming out. Mhmm. Skills are a collection of text, typically markdown, sometimes integrated like with Claude code with maybe some scripting language like TypeScript with an application like BUN to run things.
Derek Banks:Essentially, text that allow or provide the model with a consistent way of performing a task. So for example, there's a skill that I use a bunch through its part. It... You know, I've I've modified it, but part of Daniel Measler's Life OS used to be PAI called research, where it'll spawn different research agents for different model providers and go off and get different answers and bring back essentially a multi LLM researched topic, which is kinda handy. Right?
Derek Banks:And so it does it the the same way every time. And to me, it's just more of a way to provide consistent context for a large language model to more, to perform a task in a more deterministic way.
Brian Fehrman:Yeah. I think I think that's great. I think that really sums it up. You know, it's think about when you get, like, a really nice prompt that you're really excited about and things are working. Well, you don't wanna have to rewrite that every single time from scratch.
Brian Fehrman:Hence
Derek Banks:I'm I'm guilty of that. Oh,
Brian Fehrman:me too. Me too.
Derek Banks:And, you know, I really should make a skill out of this.
Brian Fehrman:Yeah. That's it. We'll do that later after I forget.
Derek Banks:Yeah. Exactly.
Brian Fehrman:Yep. So then...
Derek Banks:Go ahead. I was gonna say a malicious skill must come from a place where you get skills, such as like a marketplace. Because you know, you wouldn't necessarily write your own malicious skill. You could have your harness write a skill for you. Hermes does that a lot.
Derek Banks:Right? It's just like, yeah, part of its self learning kind of thing. It'll write a skill. But the malicious skills must come from a place.
Brian Fehrman:And where is that place? So... Well...
Derek Banks:GitHub? GitHub. Yeah. Yes. So, yeah, GitHub, there's skills marketplaces for, like, I I would assume for car...
Derek Banks:Coding harnesses. I'm gonna be honest. I don't normally go off and find third party skills. But I would say the ones that I have gone to get, like Ethan turned me on to superpowers, which is like a collection of skills, it was on GitHub.
Brian Fehrman:Mhmm.
Derek Banks:And I basically just said, hey, Claude. Go grab those and use those, and it did. So...
Brian Fehrman:Yeah. Yeah. I mean, it's like... It's with with software in general. Right?
Brian Fehrman:Like open source stuff. So, I mean, just things you can find out on the Internet. I mean, it's not all bad, but, certainly lots of good useful stuff out there that, you know, just you have to just be careful and and selective in where you're getting the stuff from, who you're getting it from, version pinning, all those good things that we've, you know, we've discussed for just kinda software in general. As a side note, Spectre Ops put out their skill set recently.
Derek Banks:Oh. Nice. Yeah. So the answer for where do you go get skills is pretty much the Internet. Yeah.
Brian Fehrman:The Internet.
Derek Banks:Yeah. You go get them from the Internet.
Brian Fehrman:So I think that that's a good quick segue into the next one, which is, I would say, semi related supply chain compromise. So...
Derek Banks:Yeah. So here's where I'll probably say, like, do we really need 10 for just skills? I feel like sometimes the OWASP folks would probably could have got by with the top five or three here. So I think certainly supply chain, it's kind of related. Right?
Derek Banks:Like, where are you getting your skill from? So if you're getting it from, I'd say, like Spectre Ops, the chances that the skill has anything malicious in it are probably pretty low because Spectre Ops has a reputation to maintain. I know that if BHIS was putting out a skill repository, and there ended up being a malicious skill in there, I'm pretty sure that there would be very unhappy folks at BHIS. Right? Like...
Derek Banks:So I I gotta say, you know, the saying, you know, Anthropic has a skill repo, which might be a little bit more Wild West y kind of thing. But, yeah, just know where you're getting your skills from, where they're coming from in the supply chain of your Agentic coding harness.
Brian Fehrman:Yeah. And also, you know, as we just mentioned to you, also, considering to do things such as version pinning, hash checking on the skills to make sure that, like, hey, This skill was good yesterday. Is it still good today? Similar things that we have seen with, the... Have talked about with the MPM compromise, PyPy compromise.
Brian Fehrman:You know, it it it might have very well been perfectly fine yesterday, and now someone got a hold of it because whatever crazy attack chain happened, and and now they've inserted malicious stuff into the supply chain.
Derek Banks:Yeah. So the defense against supply chain attacks, not just for skills, but for agents just in general, would be that if you're building software to version pin specific libraries. Probably the most, I'd say the the most famous example I can think of off the top of my head is Light LLM. That got hacked a while back, and we still still keep hearing about, like, apparently, that was a lot bigger deal than was made of at the time, just because Light LLM had... And I can't remember the detail.
Derek Banks:Something that they were using got compromised, and it was part of a supply chain issue that, I assume distributed Stealer ransomware or Stealer Stealer malware, I guess, which... Ouch. That really... That sucks. And so the the other thing that I would recommend, and I I have almost completely migrated everything I do to this, is to run your agent in some kind of isolation scenario, whether that's a docker or in a VM or something like that.
Derek Banks:I mean, I... I'm definitely guilty of running clawed code, like, natively on my machine for a while, but the more and more I've kind of evaluated the risk and changed my opinion, it scares me a little bit to do so. So I'd say that those two things, version pinning and, isolation would be where I would go.
Brian Fehrman:Yeah. I I agree. I think the isolation leads well into the, the next one here, which is overprivileged skills. So Yeah. Overprivileged skills in contrast to malicious skills.
Brian Fehrman:So the overprivileged skills... And and this is just my take on it, which I I would say that the difference is is that, the... With the over... Privilege skill, the skill itself doesn't necessarily have malicious instructions built into it. So it's not necessarily that the skill was put together with the intent of getting sensitive data moving throughout a network, ransoming the system, you know, any of those behaviors that we commonly see from threat actors.
Brian Fehrman:Instead, it's more of the equivalent of, you have a domain users who are in a group that have access to, like, every system in the environment, you know, or domain users or local admin on every single system in the environment. Something like that. Right? Where you've given more privileges than what is needed to necessarily accomplish the day to day task, and then a threat actor gets a hold of that and they can leverage it. So in the the case of a skill, maybe it's for interacting with the database, but not only can it do, like a select query, but it can also do maybe a delete query or an insert query or some other change.
Derek Banks:Or just the ability to do something outside of its sandbox that you didn't intend. Right? So maybe a good example with this, if Ethan were here, he'd kinda chuckle because something similar happened to both of us. I I was trying to get some data ready to, let's just say, generically show to management. Right?
Derek Banks:And Claw decided to to helpfully to try and create a gist to, you know, upload said manage... Like, data for management to see, and that's not what I wanted. Like, I I I didn't want that at all. Right? But it helpfully wanted to...
Derek Banks:Well, this is an obvious choice to go make this, you know, like a public gist that anybody could read so that way... And so, you know, it was overprivileged or theoretically, the skill would be overprivileged in such a way where it would leak data inadvertently. I I would put that in that... This kind of category. Even though in the green room, so to speak, I was, you know, being curmudgeony about this and the first one being separate things.
Brian Fehrman:No. I'm...
Derek Banks:You gotta get to 10.
Brian Fehrman:You gotta gotta get to 10. Yeah. I have one on Spark that... So it's about on the Spark, I've got things set up so it runs open code in server mode. So all the stuff is executing on that box, so there is a level of isolation there.
Brian Fehrman:But I was asking it to analyze, data that was in a folder. It turns out though that I had accidentally put the data in a different folder, but don't worry. OpenCode decided that it was gonna go ahead and go find that data for me.
Derek Banks:Obviously. It's like Let's just search the file system.
Brian Fehrman:It's like, hey. I don't know why. Yeah. I didn't see it here, but actually, I found it in this other folder. I'm guessing this is what you wanted.
Brian Fehrman:And it's like, well, that that is the data, but I'm not very happy that you went and found it. Yeah.
Derek Banks:That's why I was I was listening to the b h I... BHIS new news clack... Cast yesterday. I was watching it kind of as a spectator, right, while I was waiting for my daughter to be finished at practice. And I can't remember who, but somebody said that I I I can't believe we're training agents to cheat.
Derek Banks:And I was like, well, that's why they're good at hacking, because there's no cheating in hacking. Right? Like, it's... I... Like, yeah.
Derek Banks:If you give it access to do something, why would you be surprised when it, you know, quote, decides to go do the thing. Right?
Brian Fehrman:Yeah. So Yeah. Putting a putting a stake in front of a dog and telling him not to eat it.
Derek Banks:I know. Right? It's like... I'm not surprised that agents wanna cheat on benchmarks because that's what humans would do. Oh.
Derek Banks:Yeah. And we essentially train these things on basically all the human knowledge we could get our hands on. Right? So Yeah.
Brian Fehrman:So, of course, what do we think is gonna happen?
Derek Banks:Humans are lazy and wanna cheat.
Brian Fehrman:Yeah. Shocker. Yep. So he's gotta gotta put measures in place to keep keep the agents honest.
Derek Banks:That's right. That's right. Yeah. Alright. Well, on number four now, I think.
Brian Fehrman:Yep. Insecure metadata. So this one also, I feel like is a bit of a stretch to pull this out down to its own because... So I think what they're talking about here is basically within... So each skill typically has some kind of, like, level of metadata, whether it...
Brian Fehrman:Which, like, a tool name, a description. Depending on the framework or harness using, it might also have certain permissions that are declared, authors, just kinda general, like, let's say, like, top of the email type content. Right? Top of the email header type content before a skill.
Derek Banks:And I don't know that I would have put it above on the next one
Brian Fehrman:No.
Derek Banks:In terms of, risk. Right? Because it would seem like to me that for a threat actor to take advantage of this, they would have to somehow be able to write to that manifest. Mhmm. And I just...
Derek Banks:I don't... I'm having trouble envisioning a scenario where that's like, if you had the access to do that, why would you do that instead of just modifying the skill or any number of other things since you obviously have shell access now too? I mean, if we're talking about skills and harnesses... Because at least in how, you know, we've been implementing more like platform level agent kind of stuff at BHIS. They don't really use skills, so to speak.
Derek Banks:That's more of a a human using, like, a terminal user interface kind of interacting with an agent, like, and consistently doing a skill. And the reason we don't use skills is because all that stuff's just in the code, like, the harness code. Right? Because it's purpose built to do a thing. So when I I think a skill, I think of something reusable that humans can use with AI.
Derek Banks:And so I'm just... I'm I'm with you. This one, I kinda feels like a little bit of a stretch.
Brian Fehrman:Well, agree. I mean, I I have a hard time differentiating this between... From malicious skill because the... I feel like you'd have to have that, like, kind of in there for this to make a difference. I mean, just like changing the metadata around to, you know, to spoof a name or whatever, like, oh, the author was, America Online, and this is your fourteen hundred free hours or whatever.
Brian Fehrman:I mean, like, okay. But, like, it's gotta actually do something to.
Derek Banks:It was like the equivalent of changing, you know, the the the, from field, not the envelope center, but the from field in a phishing email, and that's what you're pointing out as the risk and not, like, clicking on the link Correct. And actually going to the phishing site. Like Yeah. I think the risk might be a little misplaced here, which actually kinda leads into where, you know, at least in that example, you know, the the next one, untrusted external instructions Yeah. Which sounds awful lot like indirect prompt injection to me.
Brian Fehrman:But I would agree with that. Yes. Yeah. Untrusted external instructions. That's...
Brian Fehrman:I I I think that that's just... It's, like you said, it's an indirect prompt injection by another name.
Derek Banks:Yeah. Which I... Like, I don't wanna take away from that risk at all because I... Again, you know, keeping up with the AI news over the summer, turns out that this thing we're we're creating is actually quite creative given enough, you know, time and resources. And, I guess I've started maybe trusting a little less, like, what's happening, without me proving that it's happening or not happening locally on my system.
Derek Banks:And I frequently do have agents that go reach out to the Internet and do things. Like, just mentioned that research agent that I really like to do. I do a lot... I I have Claude do a lot of OSN for me for, like, external tests. It's just...
Derek Banks:I have a skill that's just really good at it. And I combine that with, like, all the stuff that, like, is running tools, and I don't know. It's just pretty good at getting all that stuff together. But... Yeah.
Derek Banks:I mean, if I was, maybe a threat actor that had access to a website or if I was just a, you know, an unethical, like, actor altogether, maybe I'd put some stuff. I actually saw a news article recently that someone was using the... Oh, no. I remember what it was. We actually talked about this a couple episodes ago when it was just me and Bronwen about LLMs dot text and LLM dash full dot text, like a robots dot text file, where this researcher had discovered that there were these, like, essentially large language model robots dot text files that were out on government contractor and and site...
Derek Banks:Government contractor sites. A whole bunch of sites, and they had instructions that were pointing to nonexistent domain. So they went and registered them and had agents reaching out to them, to which the article implied that then they got the agents to run payloads, which again seems to me... Like, I'm not I'm not clear on how that's not a, like, a computer fraud and abuse act kind of thing, but maybe I'm using that as a big hammer these days. Like, for for things that happen with AI, it's like, oh, it...
Derek Banks:AI did it, so never mind. I guess, you know, it's okay now.
Brian Fehrman:Yeah.
Derek Banks:Like
Brian Fehrman:Yeah. I feel like people have been TFA ed for far less than that. So
Derek Banks:Right. Yeah. Exactly. Like, this whole... Like, when I read or I guess it was on the news last night, they were talking about...
Derek Banks:On the BHIS news, they were talking about the OpenAI's latest, like, things back in May. Some of their models... One of their models in a similar situation, the Hugging Face apparently was hacking some German website. And apparently, they found out in May that it didn't do anything until, like, June. Like, well, if I'm an employee at your company and you find out in May that I am using your time and resources and computing tokens and, like, I...
Derek Banks:To to hack a German website for any reason, whatever my motivations are, would you watch me for a month?
Brian Fehrman:And just about do anything. You're like, woah, wait a minute. Let's just see where they go with this.
Derek Banks:Yeah. Or I don't know. It's the, I guess nobody's responsible. I guess... I I I don't know.
Derek Banks:I think there has to be some kind of, like, logical conclusion here. At some point, the operators have to be, at least at at some level, like, culpable. Right? Like, feel like, you know, here at BHIS, if, like, the thing that we do with AI that runs, like, autonomously with agents that we've strictly scoped and put monitoring around, if something happened to them, I I would own it. I'd have to.
Derek Banks:Right? That's why we put the things in place to do, you know, the monitoring and restrictions. But, anyway, I got a little off topic. But, yeah, this is why I think that this is definitely... I would put this probably at maybe number three.
Derek Banks:Malicious skills, and then supply chain, and then I think this, because it's essentially indirect prompt injection.
Brian Fehrman:Yeah. And there are, I think, definitely interesting attack vectors from this. So the ones you described, another one that just popped in my head because it's looking through, some of our our latest, AI edge case, augmented external testing results, and it looks like we've found another site that's potentially compromised that has links to a shady gambling site embedded within the content. But That'd
Derek Banks:be two in a month.
Brian Fehrman:Two in a month. But you could also potentially use that, something like that as vehicle for the indirect prompt injection too. As within the HTML embedded, so it's not displayable, you have these instructions that you put in there that you've injected into a reputable site that is potentially being scraped and utilized by other AI agents. Like, you know, there's no version pinning there. You can't really see what's on...
Brian Fehrman:I mean, most people aren't digging through the HTML. So I think that all these kind of unique unique ways that this could manifest itself just based upon how interconnected all of our information is, and how quickly we're all gobbling up this information with our with our AI stuff. Yeah.
Derek Banks:And just wait. Threat actors are gonna be like, here, how about beer? Watch this. And they're in a fight in, like, all kinds of ways to get indirect prompt injection into the AIs that are gonna increasingly be running things. Yep.
Derek Banks:Good times. Good times. Times. That's the top five Yeah. Of the Agentic skills.
Derek Banks:I think the idea is we'll do a companion follow on episode at... Perhaps next week for the remaining five.
Brian Fehrman:Yeah. I guess the bottom five?
Derek Banks:The bottom
Brian Fehrman:five. The top five. 1%.
Derek Banks:And sometimes, just like reading those informational, like, vulnerability scan results, sometimes those infos turn into criticals. We don't discount them because somebody has said the risk is different than we think.
Brian Fehrman:Yep. We will give them the love and attention they deserve.
Derek Banks:Exactly. Alright. Probably until then, you know, keep on prompting.
Brian Fehrman:Keep on prompting. Finger guns.