Top 2026 LLM-Based Attack Detection: Fake AI Agent Skill / Installer Delivery
Detects the execution of binaries or scripts named with keywords related to AI agent plugins (e.g., 'skill', 'plugin', 'mcp-server') from potentially untrusted locations like Downloads or Temp folders. The rule further correlates this execution with post-exploitation indicators such as persistence establishment (registry keys, scheduled tasks, launch agents) or outbound network activity.
YARA-L

