India, June 24 -- A harmless-looking AI agent skill reportedly reached thousands of agents after passing security checks, gaining marketplace credibility, and being promoted through an ad. The important issue is not the exact number. It is the path it used.

Security firm AIR says it built a fake Artificial Intelligence (AI) agent skill called brand-landingpage and listed it through a popular skill marketplace. The skill claimed to help non-technical users create landing pages with Google's Stitch design tool. AIR says it later reached about 26,000 agents, including some linked to corporate accounts.

The test was designed to be safe. According to AIR, the payload only collected the user's email address. But the method points to a deeper ...