Securing the Agent Supply Chain
A developer installs a skill to make their coding agent less chatty. It works. It also, the first time the agent uses it, reads the AWS credentials on that laptop and sends them to a domain no one recognizes. No one wrote obviously malicious code and no one approved a change. A file landed in a folder, the agent loaded it on the next run, and production credentials were gone.