The Circus of Skills
We discovered that 17,822 open source skills, with a total of 6.7M installations, are vulnerable to the Untrusted External Instructions Source attack vector. This attack vector, meaning the skill fetches external instructions from untrusted sources, has been officially recognized by OWASP as one of the top 10 risks for Agentic Skills, and covers 12.4% of GitHub open source skills.