1---2name: 2592-snyk-toxicskills-evaluation-a8ae1bf33description: Resource Evaluation: Snyk ToxicSkills — Malicious AI Agent Skills Audit4---5# Resource Evaluation: Snyk ToxicSkills — Malicious AI Agent Skills Audit67| Field | Value |8|-------|-------|9| **Resource** | [Snyk ToxicSkills Blog](https://snyk.io/fr/blog/toxicskills-malicious-ai-agent-skills-clawhub/) |10| **Type** | Security research + open-source tool |11| **Published** | 2026-02-05 |12| **Relayed by** | Victor Langlois (LinkedIn) |13| **Score** | **4/5** (High Value) |14| **Action** | Integrated — enriched security-hardening.md (CVE, stats, new section §1.5) |1516---1718## Summary1920Snyk scanned **3,984 AI agent skills** across ClawHub and skills.sh marketplaces, finding:21221. **36.82%** (1,467 skills) contain security flaws232. **534 skills** flagged critical (malware, prompt injection, exposed secrets)243. **76 malicious payloads** identified (credential theft, backdoors, data exfiltration — 8 still active on ClawHub at publication)254. **10.9%** of ClawHub skills contain hardcoded secrets265. **2.9%** fetch and execute remote content dynamically276. **mcp-scan**: open-source tool achieving 90-100% recall on confirmed malicious skills, 0% false positives on top-100 legitimate skills2829## Gap Analysis3031| Topic | Before (guide) | After |32|-------|----------------|-------|33| Supply chain stats | 8-14% (SafeDep) | 36.82% (Snyk, 3,984 skills corpus) |34| Audit tools | skills-ref validate | + mcp-scan (Snyk) |35| Attack categories | Generic (injection, exfil, privesc) | 8 detailed policies (hardcoded secrets, remote prompt exec, malicious downloads) |36| .claude/ attack vector | 1-line mention (line 199) | Full section §1.5 with checklist |37| Malicious hooks/commands | Not covered | Documented with audit checklist |38| Recent CVEs | 5 CVEs (2025) | + CVE-2026-24052, CVE-2025-66032 |3940## Fact-Check4142| Claim | Verified | Source |43|-------|----------|--------|44| 3,984 skills scanned | Yes | Snyk blog |45| 36.82% with flaws (1,467/3,984) | Yes | Snyk blog |46| 534 critical | Yes | Snyk blog (13.4% of total) |47| 76 malicious payloads | Yes | Snyk blog (8 still active on ClawHub) |48| mcp-scan 90-100% recall | Yes | Snyk blog (0% FP on top-100 legit) |49| "91% combine injection + code" | Not verified | LinkedIn post stat, not in Snyk blog. Excluded from integration. |50| CVE-2026-24052 (SSRF Claude Code) | Yes | SentinelOne vulnerability database |51| CVE-2025-66032 (8 bypasses) | Yes | Flatt Security research |5253## Score Justification5455**4/5 (High Value)** — not 5/5 because:5657- The guide already covers ~70% of the scope (security-hardening.md §1.1-1.4)58- This is an enrichment (updated stats, new tool, new section), not a gap-from-scratch59- Snyk stats are more recent and larger corpus than existing SafeDep data60- mcp-scan fills a concrete tooling gap61- The .claude/ attack surface section addresses a real blind spot6263## Integration Plan64651. **§1.1 CVE Summary**: +2 CVEs (CVE-2026-24052, CVE-2025-66032)662. **§1.2 Supply Chain**: Replace SafeDep stats with Snyk (larger corpus), add mcp-scan673. **MCP Safe List**: Add mcp-scan entry684. **New §1.5**: Malicious Extensions (.claude/ Attack Surface) with audit checklist695. **reference.yaml**: Add entries for new sections7071## References7273- **Snyk ToxicSkills**: [snyk.io/blog/toxicskills](https://snyk.io/fr/blog/toxicskills-malicious-ai-agent-skills-clawhub/)74- **mcp-scan**: [github.com/snyk/mcp-scan](https://github.com/snyk/mcp-scan)75- **CVE-2026-24052**: [SentinelOne](https://sentinelone.com/vulnerability-database/)76- **CVE-2025-66032**: [Flatt Security](https://flatt.tech/research/posts/)77- **SafeDep (previous source)**: [safedep.io/agent-skills-threat-model](https://safedep.io/agent-skills-threat-model)