[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f6-S9mPeNxr8uEgI2AfGHQMcly6IgH4XREeN51_FQA_E":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":20,"created_at":21,"published_at":22,"article":23,"tags":27,"podcasts":46},"0df8b2f2-9661-409c-91c7-19487c4d013f","placeholder-domains-in-ai-agent-skills-hijacked-to-serve-scams","dc77bf2c-1c0e-482c-a0f5-9cfb38d26226","Placeholder Domains in AI Agent Skills Hijacked to Serve Scams","Developers commonly use placeholder or example domains (e.g., 'example.com' or 'yourdomain.com') in code templates, AI agent skill definitions, and configuration files without verifying ownership or replacing them before deployment. Malicious actors have exploited this oversight by registering or redirecting these unclaimed domains to scam and malware sites, affecting 349 AI agent skills and over 359,000 GitHub files. This represents a serious supply chain vulnerability, as AI agents that call these domains can silently redirect users to fraudulent content without any obvious warning. The scale of exposure — spanning public repositories and packaged AI skills — demonstrates how a seemingly minor development shortcut can become a widespread attack vector at the ecosystem level.","**Immediate actions:**\n- Audit all AI agent skill definitions and code repositories to identify any placeholder or unverified domains and replace or remove them immediately.\n- Perform WHOIS lookups and domain validation checks on every external domain referenced in AI skills, templates, or configuration files before deployment.\n\n**Long-term improvements:**\n- Establish a mandatory domain validation policy requiring all referenced domains to be owned, verified, and monitored as part of the software development lifecycle.\n- Implement automated static analysis tools in CI\u002FCD pipelines to flag placeholder, unregistered, or suspicious domains in code and configuration files.\n- Maintain a curated, approved allowlist of external domains that AI agents are permitted to contact, blocking all others by default.\n\n**Detection measures:**\n- Monitor outbound DNS queries and HTTP requests from AI agents to detect unexpected or newly registered domain redirections at runtime.\n- Subscribe to threat intelligence feeds that track domain reputation changes, enabling rapid identification when a previously safe domain is hijacked or redirected.",[12,13,14,15,16,17,18,19],"CIS Control 2: Inventory and Control of Software Assets","CIS Control 16: Application Software Security","NIST SP 800-161: Supply Chain Risk Management Practices","NIST CSF DE.CM-6: External Service Provider Activity Monitoring","NIST SP 800-53 SA-12: Supply Chain Protection","NIST SP 800-53 CM-7: Least Functionality \u002F Allowlisting","OWASP Top 10 A08:2021 – Software and Data Integrity Failures","ISO\u002FIEC 27036: Information Security for Supplier Relationships","published","2026-09-26T20:20:37.17294+00:00","2026-09-26T20:20:37.092+00:00",{"id":7,"url":24,"slug":25,"title":26},"https:\u002F\u002Fhackread.com\u002Fplaceholder-domains-ai-agent-skills-redirect-scams\u002F","placeholder-domains-used-by-349-ai-agent-skills-found-redirecting-to-scams-fd0f94","Placeholder Domains Used by 349 AI Agent Skills Found Redirecting to Scams",[28,34,40],{"id":29,"name":30,"slug":31,"description":32,"color":33},"05757c8d-6b93-4194-b35d-7359e7d33b0e","Vulnerability Management","vulnerability-management","Missing scans, no risk prioritization","#fb923c",{"id":35,"name":36,"slug":37,"description":38,"color":39},"859cf0ad-a7e9-42bb-a75d-bac6511fa5d5","Configuration Management","configuration-management","Misconfigs, default credentials, exposed services","#eab308",{"id":41,"name":42,"slug":43,"description":44,"color":45},"f0c2a0af-58aa-4128-87c9-6acd30f2dc48","Supply Chain","supply-chain","Third-party risk, compromised dependencies","#8b5cf6",[47],{"id":48,"date":49,"edition":50,"title":51,"audio_url":52},"13c8d089-3c57-4fc1-a760-c0f278e03864","2026-09-27","morning","ThreatNoir Weekend Brief — September 27","https:\u002F\u002Fcdn.threatnoir.com\u002Fpodcasts\u002F2026-09-27\u002Fthreatnoir-morning-brief-2026-09-27.mp3"]