CertiK addresses vulnerabilities in AI agent marketplaces, warns skill scanning alone is insufficient, urges runtime security and stronger protection measures.CertiK addresses vulnerabilities in AI agent marketplaces, warns skill scanning alone is insufficient, urges runtime security and stronger protection measures.

CertiK Warns Security Risks in AI Agent Marketplaces Despite Next-Gen Skill Scanning

2026/03/17 20:42
Okuma süresi: 2 dk
Bu içerikle ilgili geri bildirim veya endişeleriniz için lütfen [email protected] üzerinden bizimle iletişime geçin.
certik

The researchers from CertiK, a renowned blockchain security entity, have recently uncovered a crucial security lapse in the latest AI agent networks. Hence, the new report from CertiK’s lead researcher, Guanxing Wen, warns against the insufficiency of just skill scanning when it comes to ensuring safety.

As CertiK mentioned in its official press release, a legitimate 3rd-party “Skill” could circumvent moderation checks on the OpenClaw platform. The malicious Skill was even capable of executing arbitrary commands via the host system, irrespective of passing diverse review layers.

CertiK Uncovers Deficiency of AI Skill Detection and Review System in Securing AI Agent Marketplaces

As CertiK’s analysis discloses, Clawhub, the AI agent marketplace of OpenClaw, depends on a multi-layered pipeline of reviews, including unchangeable code scanning, AI-led moderation, and VirusTotal checks. Though these mechanisms focus on identifying malicious behavior, CertiK’s researchers found that prudently structured logic and minute code modifications can conveniently circumvent detection.

In several cases, Skills that seem benign during the process of installation may contain manipulable vulnerabilities concealed within normal workflows.The research stresses the inherent limitation of static detection methods.

Just like conventional cybersecurity tools such as web app firewalls or antivirus software, pattern-based identification can be circumvented via minor code structure variations. Additionally, while artificial intelligence (AI) moderation enhances detection with the analysis of inconsistencies and intent, it is still deficient at unearthing deeply integrated vulnerabilities.

Blockchain Security Platform Recommends Runtime-Based Security and Resilient Skill Isolation

According to CertiK, its proof-of-concept has further disclosed a flaw in the handling of pending security audits. Specifically, Skills could reportedly become openly installable and available even at a time when VirusTotal results appear incomplete.

Keeping this in view, CertiK’s study encourages the enhancement of detection rather than relying on user warnings and marketplace reviews. As a result, without solid runtime protection, even a single overlooked vulnerability can result in compromise of the whole host environment.

Amid the wider growth of AI ecosystems, CertiK pushes toward the adoption of runtime-based security frameworks, enhanced 3rd-party Skills isolation, and stringent permission controls. So, comprehensive security will rely on establishing mechanisms that assume some threats to bypass review to ensure the containment of such threats ahead of any harm.

Sorumluluk Reddi: Bu sitede yeniden yayınlanan makaleler, halka açık platformlardan alınmıştır ve yalnızca bilgilendirme amaçlıdır. MEXC'nin görüşlerini yansıtmayabilir. Tüm hakları telif sahiplerine aittir. Herhangi bir içeriğin üçüncü taraf haklarını ihlal ettiğini düşünüyorsanız, kaldırılması için lütfen [email protected] ile iletişime geçin. MEXC, içeriğin doğruluğu, eksiksizliği veya güncelliği konusunda hiçbir garanti vermez ve sağlanan bilgilere dayalı olarak alınan herhangi bir eylemden sorumlu değildir. İçerik, finansal, yasal veya diğer profesyonel tavsiye niteliğinde değildir ve MEXC tarafından bir tavsiye veya onay olarak değerlendirilmemelidir.