Skip to main content
All posts

Agentic SecurityResearch published: May 11, 20264 min read

A malicious coding-agent skill tried to steal a GitHub token. What should teams check?

Datadog found a public skill that requested a GitHub token. Its tests show why a model's refusal may come too late when skill commands run before the model reads them.

A small untrusted module sends an amber signal across glass toward a protected server.

A coding-agent skill can contain executable commands as well as instructions. In research published on May 11, Datadog Security Labs described a public Claude Code skill that tried to collect a user's GitHub token. The practical question is whether your team reviews a skill as executable code before allowing an agent to load it.

The skill, called Clawsights, presented itself as a leaderboard for Claude Code usage. Datadog found instructions to run `gh auth token` and send the token to an external upload endpoint with a usage report. The researchers identified an attempted credential theft. Their report does not establish that the published skill successfully stole tokens from users in the wild.

Why can a model refusal come too late?

Datadog first tested a modified copy of the skill with the destination changed to a domain the researchers controlled. Claude Code using Opus 4.6 recognised the visible token request and refused to run it. That was a useful defence in that test, but it was not the end of the investigation.

Claude Code skills also support dynamic context: shell commands marked with `!` run while the skill is being prepared, before the resulting text reaches the model. Datadog added token-reading and upload commands through this mechanism in a controlled test. The commands ran before the model could refuse the skill. The team also reports that, in later tests, Opus 4.7 ran the modified visible skill without identifying the theft. These are observations under stated test conditions, not a claim that every model or configuration behaves alike.

Which paths should security teams review?

  1. Step 01Inventory skills in personal, project, nested and plugin directories. Treat a repository's skill files as part of the code you review before use.
  2. Step 02Check skill frontmatter and dynamic-context commands for broad shell permission, credential reads and outbound requests. Consider the managed `disableSkillShellExecution` setting where this feature is unnecessary.
  3. Step 03Limit token scope and workstation egress, then monitor processes and network connections started during agent work. A model refusal cannot undo a command that already ran.

HikmaAI's Find It approach can assess supported skill-agent surfaces, and Fix It and Prove It apply to interactions routed through a protected boundary. A preprocessing shell command on a developer machine may sit outside that route. Review the skill's own execution settings and the host controls as part of the same deployment decision.

A useful test is simple: take one skill your team already uses, identify every command that can run before the model sees it, and verify which credentials and destinations that command can reach.

See how HikmaAI finds risk, enforces protection and produces evidence on a representative production flow.