Security researchers at Zenity Labs uncovered a credential-stealing campaign on skills.sh, a public registry of add-ons for AI agents run by Vercel. Those told the AI agents to hunt down SSH keys, cloud credentials, database logins and access tokens, bundle them with the machine’s details, and ship them to attacker servers. A skill is just instructions, and an agent’s whole job is to follow instructions from the content it is handed. One skill told the agent to rewrite its own system prompt so it would reinstall itself if deleted. For an AI agent it is no longer just code libraries, but skills, tools, MCP servers and any web page it reads.