February 2026Unreviewed
Formal Analysis and Supply Chain Security for Agentic AI Skills
Varun Pratap Bhardwaj
arXiv.org
Abstract
The rapid proliferation of agentic AI skill ecosystems -- exemplified by OpenClaw (228,000 GitHub stars) and Anthropic Agent Skills (75,600 stars) -- has introduced a critical supply chain attack surface. The ClawHavoc campaign (January-February 2026) infiltrated over 1,200 malicious skills into the OpenClaw marketplace, while MalTool catalogued 6,487 malicious tools that evade conventional detection. In response, twelve reactive security tools emerged, yet all rely on heuristic methods that pro
Categories
Framework mappings
OWASP Top 10 for LLM Applications
- LLM03Supply Chain
MITRE ATLAS
- AML.T0010AI Supply Chain Compromise
Suggested from the entry's categories.
Cite
@misc{bhardwaj2026formal,
title = {{Formal Analysis and Supply Chain Security for Agentic AI Skills}},
author = {Varun Pratap Bhardwaj},
year = {2026},
month = feb,
eprint = {2603.00195},
archivePrefix = {arXiv},
doi = {10.5281/zenodo.18787663},
url = {https://www.semanticscholar.org/paper/d6665127102362bd5060d673a21fe6b1de3f376c}
}