تخطي إلى المحتوى الرئيسي
Cyber News Dark Reading 4 hours ago

OWASP Flags Top AI Skill Risks in New Security Blueprint

Da
Dark Reading

In early July, a cyberattacker reserved a look-alike domain impersonating a popular agentic AI work platform, Paperclip, and produced both Trojanized Python packages and weaponized AI skills to compromise users' machines and steal a variety of credentials and sensitive information. The incident showcases why the Open Worldwide Application Security Project (OWASP) decided to poll practitioners earlier this year on that type of risk, which has now resulted in a first-of-its-kind candidate list of the top 10 security issues for agentic skills. Holding the current No. 1 spot? Malicious Skills.

The ability to add on features and capabilities through "skills" — natural-language and coded recipes for agentic platforms — makes AI agents much more capable but also adds a significant vector for untrusted input and malicious code, while a lack of security models and capabilities makes even legitimate skills subject to abuse. So, the OWASP move appears necessary: In the July incident, for example, automated scanners detected the Python packages within hours. The Trojanized skills, however, escaped detection and quickly racked up more than 300,000 installs each, according to research published on Aug. 6.

Related:OpenAI Adds Controls That Should've Been There Already

Inside OWASP's Fresh Top 10 AI Skills Risk List

This week, OWASP released its final version of the list and an initial attempt at a standardized YAML format for skills files that can help automated analysis determine which skills are legitimate and which are not.

The intent of the list is to highlight the dangers posed by skills and the risks that agent developers should address, says Omar Turner, a security practitioner supporting the effort whose day job is managing director of cloud and AI security projects at Microsoft. He tells Dark Reading that many discussions at the recent Black Hat USA Conference focused on agents, but few focused on skills.

"Without the knowledge of what risks could exist with skills, you're kind of operating blind," he says in his OWASP-support capacity. "The concept of skills, the risks with skills, and the potential of threat actors could leverage skills in a certain way has to be reviewed and thought about with a conversation in organizations just like agents are right now."

View Original Report

This intelligence was aggregated from Dark Reading.

Read on Source
Advertisement