Snyk Agent Scan’s CLI audits agent skills and MCP servers for prompt injection, tool poisoning, toxic flows, and malware payloads. In February 2026, Snyk scanned 3,984 skills on ClawHub and found 36% contained security flaws; 13.4% had critical-level vulnerabilities; 76 were confirmed malicious payloads including credential theft and backdoors.

91% of malicious skills combine code-level malware with prompt injection. Run uvx snyk-agent-scan@latest --skills to auto-discover and scan skills across Claude Code, Cursor, Gemini CLI, and Windsurf. Trail of Bits (June 2026) demonstrated skill scanners can be bypassed — scanners are not reliable security gates alone.