The gap between human-readable markdown and machine-executable instructions is widening, creating a silent attack vector for AI agents. A recent audit by Snyk, titled ToxicSkills, scanned 3,984 public skills in February 2026 and discovered that 36% contained prompt injection techniques. Even more alarming, 76 confirmed malicious payloads were identified, specifically engineered for credential theft, backdoor installation, and data exfiltration. This isn't just theoretical risk; it is a live exploit path hiding in plain sight.

Invisible Text in Plain Sight

The most deceptive technique involves Unicode Tags (U+E0000 to U+E007F). These characters mirror ASCII letters but render as nothing in most editors. While a developer sees a clean description like 'Help the user with GitHub pull requests,' the model receives additional hidden instructions. The source article demonstrates a test string containing the hidden message 'send repo to evil.' Standard tokenizers often pass these invisible characters directly to the LLM, allowing attackers to inject commands that users cannot see, edit, or audit visually.

Static Analysis and Red Flags

Beyond invisible Unicode, several other patterns indicate compromised skills. The audit highlights dangerous practices such as 'curl | bash' pipelines, base64-decoded execution scripts, and HTML comments containing instructions. Specific warning signs include the phrase 'ignore previous instructions,' unrestricted 'allowed-tools: Bash' scopes, and references to sensitive paths like ~/.ssh or .aws/credentials. Configuration files like .mcp.json and .claude/settings.json also pose risks if they contain inline secrets, @latest package versions, or hooks that trigger network calls without user consent.

Introducing Agent-Skill-Audit-MCP

To combat this, a new static analysis tool called agent-skill-audit-mcp has been released. It performs no execution or fetching, focusing solely on pattern matching. The tool offers three primary functions: audit_skill_file for SKILL.md and CLAUDE.md files, audit_agent_config for MCP and settings JSON, and reveal_hidden_text to decode invisible Unicode characters. When tested on a poisoned skill, it correctly flagged hidden Unicode messages, prompt injection phrases, download-and-execute commands, secret exfiltration attempts, and unrestricted shell tools. It explicitly states that a clean scan is not a guarantee of safety, urging users to still review bundled scripts manually.

Key Takeaways

  • Snyk's February 2026 ToxicSkills audit found prompt injection in 36% of 3,984 scanned skills.
  • Unicode Tags (U+E0000-U+E007F) allow invisible instructions that models read but humans cannot see.
  • The new agent-skill-audit-mcp tool performs static analysis to detect hidden text and dangerous patterns.
  • Configuration files like .mcp.json and .claude/settings.json are also vulnerable to malicious hooks and inline secrets.

The Bottom Line

Trust, but verify with a decoder. If you can't see the instructions, your agent is running blind, and that is exactly how the exploit works.