Agent-Based Scanner Catches 95% of Malicious AI Skills vs. 8% for Static Tools

Researchers at Trent AI benchmarked five ClawHub skill scanners against a manually labelled set of 60 skills, covering benign, vulnerable, and malicious categories. Their agent-based scanner, trentclaw, achieved a 94.6% recall rate — over 40 percentage points higher than the next-best tool, ClawScan, which caught 54.1%. Signature and static analysis scanners performed worst, flagging as few as 8.1% of dangerous skills. The study found that reasoning-based scanners outperform pattern-matching tools partly because some malicious skills ship with no executable code, making them invisible to signature checkers. The benchmark comes amid real-world threats like the February 2026 ClawHavoc campaign, in which disguised productivity skills were used to steal API keys and browser credentials from users.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.

Discussion (0)
Log in to join the discussion and vote.
Log in