INTEL_REPORT
Trail of Bits — Security engineering · published 6/3/2026, 11:00:00 AM · TLP amber
Summary
Ingested excerpt (first ~500 chars of normalized text).
The sorry state of skill distribution Public skill marketplaces are being flooded with malicious skills that steal credentials, exfiltrate data, and hijack agents. In response, a segment of the security industry released skill scanners, a new family of tools designed to detect malicious skills before they’re installed. But we tested them, and they don’t work. We recently bypassed ClawHub’s malicious skill detector , Cisco’s agent skill scanner , and all three of the scanners…
https://blog.trailofbits.com/2026/06/03/the-sorry-state-of-skill-distribution
sha256:ed1a3a4f7905ad9cd5101e8225f99e10cab665a33b930e868dd4c610e6ccfc71
What we pulled out
Deterministic extractor (IOC + allowlisted tokens + ATT&CK IDs present in DB).
Indicators
Linked with report → mentions → indicator. Values open the indicator workspace.
Malware families
Allowlist token matches only.
Threat actors mentioned
Allowlist mentions — not a formal attribution verdict.
ATT&CK techniques
MITRE IDs referenced in text and present in local technique table.
CONTINUE INVESTIGATION
High-signal pivots without leaving the thread you started in search.
Browse the report corpus.
Neighborhood from the first linked indicator.
| utils.py |
| Open → |
| domain | utils.cpython-312.pyc | Open → |
| domain | npm.internal-artifacts.corp.dev | Open → |
| domain | bootstrap.sh | Open → |
| domain | soffice.py | Open → |
| url | https://www.npmjs.com/org/corp | Open → |
| url | https://npm.internal-artifacts.corp.dev | Open → |
| url | https://npm.internal-artifacts.corp.dev` | Open → |
| url | https://npm.internal-artifacts.corp.dev\ | Open → |