Too Big To Ignore? The Security Crisis Brewing In AI Agent Platforms
ESET, Friday, March 20th, 2026
What we found after scanning 60 thousand skills for AI agents, and how to put guardrails in place.
AI systems don't just answer questions, they plan, browse, and take actions on your behalf. That leap from chat to autonomy, popularized by the OpenClaw project, is largely powered by 'skills' - small tools or add‑ons that instruct an agent how to perform a task, including which services to use and what actions to take.
However, with great power comes great responsibility. As capabilities grow, so does the attack surface - especially when users install new skills into highly privileged AI agents without any security review.