Skip to content

Hide Navigation Hide TOC

Skill Data Exfiltration via Compound Patterns - ATR-2026-00149 (b73d8b7c-3528-5532-a0ed-3d2188fd9749)

Detects compound exfiltration patterns in SKILL.md files where sensitive data (credentials, SSH keys, wallet files, browser data, environment variables) is read AND transmitted to an external endpoint. Single-action patterns (just reading env vars or just mentioning curl) are intentionally excluded to avoid false positives on legitimate security and DevOps skills.

Cluster A Galaxy A Cluster B Galaxy B Level
ML Supply Chain Compromise (d2cf31e0-a550-4fe0-8fdb-8941b3ac00d9) MITRE ATLAS Attack Pattern Skill Data Exfiltration via Compound Patterns - ATR-2026-00149 (b73d8b7c-3528-5532-a0ed-3d2188fd9749) Agent Threat Rules 1