Poisoned Claude SKILL.md Hidden Prompt-Injection Payload
Detects malicious markdown files (SKILL.md) that impersonate agent instruction files. These files contain hidden-content constructs (like CSS display:none, HTML comments, or invisible Unicode characters) combined with common command execution patterns (like curl, wget, or PowerShell encoded commands), characteristic of infostealer campaigns targeting AI agent platforms.
YARA

