CertiK addresses vulnerabilities in AI agent marketplaces, warns skill scanning alone is insufficient, urges runtime security and stronger protection measures.CertiK addresses vulnerabilities in AI agent marketplaces, warns skill scanning alone is insufficient, urges runtime security and stronger protection measures.

CertiK Warns Security Risks in AI Agent Marketplaces Despite Next-Gen Skill Scanning

For feedback or concerns regarding this content, please contact us at [email protected]
certik

The researchers from CertiK, a renowned blockchain security entity, have recently uncovered a crucial security lapse in the latest AI agent networks. Hence, the new report from CertiK’s lead researcher, Guanxing Wen, warns against the insufficiency of just skill scanning when it comes to ensuring safety.

As CertiK mentioned in its official press release, a legitimate 3rd-party “Skill” could circumvent moderation checks on the OpenClaw platform. The malicious Skill was even capable of executing arbitrary commands via the host system, irrespective of passing diverse review layers.

CertiK Uncovers Deficiency of AI Skill Detection and Review System in Securing AI Agent Marketplaces

As CertiK’s analysis discloses, Clawhub, the AI agent marketplace of OpenClaw, depends on a multi-layered pipeline of reviews, including unchangeable code scanning, AI-led moderation, and VirusTotal checks. Though these mechanisms focus on identifying malicious behavior, CertiK’s researchers found that prudently structured logic and minute code modifications can conveniently circumvent detection.

In several cases, Skills that seem benign during the process of installation may contain manipulable vulnerabilities concealed within normal workflows.The research stresses the inherent limitation of static detection methods.

Just like conventional cybersecurity tools such as web app firewalls or antivirus software, pattern-based identification can be circumvented via minor code structure variations. Additionally, while artificial intelligence (AI) moderation enhances detection with the analysis of inconsistencies and intent, it is still deficient at unearthing deeply integrated vulnerabilities.

Blockchain Security Platform Recommends Runtime-Based Security and Resilient Skill Isolation

According to CertiK, its proof-of-concept has further disclosed a flaw in the handling of pending security audits. Specifically, Skills could reportedly become openly installable and available even at a time when VirusTotal results appear incomplete.

Keeping this in view, CertiK’s study encourages the enhancement of detection rather than relying on user warnings and marketplace reviews. As a result, without solid runtime protection, even a single overlooked vulnerability can result in compromise of the whole host environment.

Amid the wider growth of AI ecosystems, CertiK pushes toward the adoption of runtime-based security frameworks, enhanced 3rd-party Skills isolation, and stringent permission controls. So, comprehensive security will rely on establishing mechanisms that assume some threats to bypass review to ensure the containment of such threats ahead of any harm.

Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact [email protected] for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.
Tags:

You May Also Like

MSTR’s latest BTC purchase offers insight into its evolving funding model

MSTR’s latest BTC purchase offers insight into its evolving funding model

The post MSTR’s latest BTC purchase offers insight into its evolving funding model appeared on BitcoinEthereumNews.com. Strategy (MSTR) has, for the first time
Share
BitcoinEthereumNews2026/03/18 09:54
PEPE Holders Looking For The Next 100x Crypto Set Their Sights On Layer Brett Presale

PEPE Holders Looking For The Next 100x Crypto Set Their Sights On Layer Brett Presale

The post PEPE Holders Looking For The Next 100x Crypto Set Their Sights On Layer Brett Presale appeared on BitcoinEthereumNews.com. Crypto News 18 September 2025 | 01:13 The Shiba Inu price prediction has regained investor attention this month as meme coin traders shift strategies ahead of Q4. While SHIB and PEPE continue to dominate headlines, many early holders are now hunting for the next breakout. Layer Brett (LBRETT), a new Ethereum Layer 2 meme coin, is quickly emerging as a top contender. Shiba Inu price prediction: Ecosystem grows but limited short-term upside Shiba Inu (SHIB) is currently priced at $0.00001307, showing slow but steady performance this September. Despite the relatively quiet price action, SHIB’s long-term vision is continuing to take shape. With the rollout of Shibarium, its Layer 2 network, Shiba Inu is transitioning from meme coin status to ecosystem coin. That said, analysts believe that short-term price action remains capped unless broader meme coin interest returns in full force. Resistance levels near $0.000015 remain tough to crack without major catalysts or a spike in retail enthusiasm. For now, Shiba Inu price predictions remain cautious, with most calling for gradual moves higher rather than a sudden breakout. Still, SHIB’s loyal community and expanding ecosystem keep it on the radar for long-term holders, especially those betting on its metaverse and DeFi ambitions to mature into stronger use cases by 2025. PEPE struggles to reclaim momentum after early hype PEPE exploded onto the meme coin scene in 2023 and gained massive traction with retail investors. However, the token’s parabolic rise was followed by a sharp correction. Currently priced around $0.00001087, PEPE still maintains a large following, but the lack of clear development or new utilities has left holders searching for alternatives with more potential. With many early PEPE investors now down from peak levels, attention has shifted to lower-cap meme coins that offer actual utility and early entry benefits. While PEPE may…
Share
BitcoinEthereumNews2025/09/18 07:02
Tim Scott expects stablecoin yield compromise proposal by week’s end

Tim Scott expects stablecoin yield compromise proposal by week’s end

The post Tim Scott expects stablecoin yield compromise proposal by week’s end appeared on BitcoinEthereumNews.com. Senator Tim Scott, chair of the Senate Banking
Share
BitcoinEthereumNews2026/03/18 10:04