AI skills are one of the fastest ways to get more out of tools like Claude, Copilot and ChatGPT. Install a skill, and your AI gains new instructions, new context, sometimes new capabilities. Productivity goes up. So does risk.
A skill is a package of files, usually Markdown instructions, that tells an AI tool how to behave for a specific task. Some skills stay within those instructions. Others can execute code, install packages, access files on your machine, call external services or read data from your connected apps. That second category deserves the same scrutiny you'd give any software you install on a company laptop.
A malicious skill can include hidden or obfuscated instructions that manipulate the AI's behaviour. It might tell the AI to ignore its safety rules, misuse connected tools, or quietly send sensitive information to an external service. The instructions look like plain text, so they don't trigger the same alarms as a suspicious executable.
This isn't theoretical. In January 2026, researchers identified the ClawHavoc campaign: a coordinated supply chain attack on the OpenClaw skill marketplace. Attackers registered as developers and uploaded 1,184 malicious skill packages across 12 author accounts. The skills had plausible names and descriptions (productivity tools, data formatters, code helpers) with encoded prompt injection payloads hidden inside their Markdown files. Of those, 335 used fake prerequisite prompts to trick users into installing Atomic Stealer (AMOS), a macOS infostealer that harvested API keys, browser credentials, SSH keys and other sensitive data. The campaign ran for 17 days before detection and compromised an estimated 300,000 users.
Attackers can also impersonate trusted brands or popular services, making a malicious skill look legitimate. A familiar name and logo aren't proof of origin. You need to verify the publisher and source repository independently.
If a malicious skill exfiltrates personal information, it may constitute an eligible data breach under Australia's Notifiable Data Breaches (NDB) scheme. Under the Privacy Act 1988, any organisation the Act covers must notify affected individuals and the Office of the Australian Information Commissioner (OAIC) when a breach is likely to result in serious harm.
The OAIC has confirmed that entering personal information into an AI tool engages Australian Privacy Principle 6 (use and disclosure), and that privacy obligations extend to personal information in AI output. The penalties are real: since the 2022 amendments, the maximum civil penalty for serious or repeated breaches is the greater of $50 million, three times any benefit obtained, or 30% of adjusted Australian turnover.
The OAIC received 1,205 data breach notifications in 2025, an 8% increase on 2024 and the highest number since the NDB scheme began in 2018. AI-related incidents are a growing area of regulatory attention.
Treat installing a skill like installing software. The checklist below covers the essentials.
Stop if any of these are true:
The publisher or repo doesn't match the claimed brand
Instructions tell the AI to ignore rules, hide actions or send data externally
You find hidden text, encoded payloads, or commands that download and execute remote code
The skill reads credentials, SSH keys, wallets or .env files
It fetches additional instructions from a URL at runtime
The skill auto-updates itself
Before you enable it:
Read every Markdown file and script in the package
Write down the tools, files, network access and credentials it needs, then cut anything unnecessary
Run it first in isolation, with dummy data
Approve tool use manually as it happens during execution
Record the owner, version and next review date
Putting a blanket ban on skills is tempting but counterproductive. People will find workarounds, and those workarounds won't have any governance around them at all.
A skill that provides a clear set of instructions is genuinely useful. It helps the AI run a specific task the same way every time, with the context it needs and the guardrails you've set. That's worth having.
The answer isn't to avoid skills. It's to vet them properly, limit their permissions to what the job actually requires, and review them on every update. A marketplace listing and a star count aren't a security review.
If your team is adopting AI tools and you're not sure how skills fit into your governance framework, that's a conversation worth having before the first install, not after.