block #0002 in --:--:--Join the pool
PENDING…
ai ✓ confirmed 6/6 44 min ago · 3 min read

Zenity AI Total detonates agent skills before you trust them

Zenity AI Total launched Oct 2, 2026 as a free detonation sandbox for agent skills, with Labs research on large malicious install campaigns.

Zenity AI Total detonates agent skills before you trust them
tl;dr
  • Zenity Labs says AI Total runs a skill inside a contained agent sandbox, baits it with planted credentials, records domains, packages, files, commands, and tool calls, then compares claimed behavior to observed behavior.
  • Pre-launch research on the same post describes a credential-stealing campaign via skills.sh reaching roughly 1.7M installs, one skill with 250,000+ installs, and more than 30% of malicious skills telling the agent to download attacker files.
  • Confirmations sit at 6 for the product launch itself because the primary is official; independent desk pickup was thin on this fetch.
in this block
  1. What actually happened
  2. Who it is for, and what it is not
  3. Practical reader checklist
  4. What to do as a reader

Zenity AI Total launched as a free public detonation sandbox for agent skills on October 2, 2026, and the numbers in this article come from Zenity's own product post rather than from invented third-party tallies.

What actually happened

Zenity's Oct 2 blog, authored by Refael (Rafa) Lachmish, argues that agent skills — small packages of instructions and scripts loaded by tools like Claude Code and OpenClaw — became a fast dependency layer with weak inspection. Static scanners read markdown and scripts; attackers shifted payloads behind runtime fetches, install-time hostility, or prompt text that talks an LLM reviewer out of a flag. The product is framed as the malware-style answer: detonate, do not merely read.

The Detonation Chamber workflow has four beats on the post: activate a real agent with realistic tasks, bait the sandbox with planted credentials and sensitive files, record everything the skill causes the agent to do, then issue a verdict from the gap between claims and behavior. Output is behavioral evidence — domains contacted, files touched, commands run — not a red/green score meant to be trusted blindly. If a "PDF formatter" phones home and reads ~/.aws/credentials, the point of Zenity AI Total is that you see those actions before the skill sits inside your agent loop.

Scale findings Zenity attributes to detonating thousands of public skills before launch: dozens malicious and missed by static tools; a credential-stealing campaign through Vercel's skills.sh at roughly 1.7M installs; one skill above 250,000 installs that sat undetected for months inside a registry's top 150; over 30% of malicious skills instructing agents including Claude Code and OpenClaw to download and run attacker files; a "reinstaller" that edits the agent system prompt to survive deletion; an impostor that removed Claude's skill-creator and replaced it; and typosquatting infrastructure around an unverified Python dependency with hundreds of reserved empty names. Zenity says these were built malicious, not hijacked after the fact. None of those rows invent numbers beyond the official post.

Who it is for, and what it is not

The post targets developers before they add a public skill, security teams approving org-wide skills, and researchers hunting techniques. The product is free at aitotal.io per the launch note. Zenity plans to extend the idea beyond skills to more untrusted agent inputs. This desk did not find a second independent newsroom write-up on the same day with matching tables; if one appears later, update confirmations and attribution. Until then, treat research percentages as Zenity Labs' claims from the official post.

Primary source: Introducing AI Total. Adjacent memcool AI security / agent reading: Personal Agent Gateway and Decagon Voice 3. For model-release contrast see Gemini 4 Argon.

Practical reader checklist

Before you install a skill from a public registry, submit it to a detonation tool you trust, read the domains and file touches, and compare them to the skill's README. Popularity and install counts are not trust signals on Zenity's own evidence. Shared service accounts and static API keys in agent stacks remain a separate identity problem, but the skill supply chain is the lane this launch addresses. Dynamic analysis costs more than a markdown lint; Zenity argues the attacks it found were designed to beat static review, which is why the company paid for real execution inside a sandbox rather than another classifier score.

What to do as a reader

If you only need the headline, Zenity AI Total is a free Oct 2 sandbox that detonates agent skills, with Zenity reporting large malicious install campaigns and runtime dropper patterns static tools missed. Verify on aitotal.io. Nothing here is a suggestion to buy Zenity equity or any token. Not financial advice. DYOR, ser.

Not financial advice. DYOR, ser.

More in the pool

all ai
gm ser

Get confirmed before the crowd

Daily block at 07:00 UTC. No spam, just the block, ser.