Placeholder Domains Embedded in AI Skills Redirect Users to Fraudulent Sites, Researchers Find
Security researchers at Manifold Security have uncovered a widespread abuse of placeholder domains that appear in thousands of code repositories and a growing number of AI agent "skills." The investigation revealed that 349 distinct AI skills were configured to silently forward users to malicious web pages, exploiting the trust users place in AI-driven assistants.
The analysis began with a sweep of more than 359,000 files on GitHub that referenced placeholder URLs—domains typically used as temporary stand‑ins during development. While many such entries are benign, the researchers found a subset that were deliberately pointed at sites designed to harvest credentials, deliver phishing pages, or serve other fraudulent content. By tracing the redirects, Manifold Security confirmed that the domains were not merely inactive placeholders but active conduits for scams.
AI agents, particularly those that support third‑party extensions or "skills," rely on external endpoints to fetch data or perform actions on behalf of users. When a skill’s configuration includes a domain that silently redirects, the AI may unwittingly present malicious content as part of its response. The 349 compromised skills span a range of popular platforms, meaning that users of mainstream voice assistants or chat‑based bots could encounter the scams without any obvious warning.
Industry experts warn that this technique is especially insidious because it leverages the perceived legitimacy of AI assistants. Users often assume that a skill vetted by a platform’s marketplace has undergone security review, yet the placeholder domain approach can bypass such checks if the redirect is only triggered at runtime. Moreover, the sheer volume of affected GitHub files suggests that the vulnerable code snippets have been widely shared, increasing the likelihood of inadvertent inclusion in new projects.
Manifold Security’s findings underscore the need for tighter validation of external endpoints in AI ecosystems. Platform operators are being urged to implement automated scanning for redirect chains and to require developers to declare any third‑party domains used by their skills. Some security analysts also recommend that developers avoid placeholder domains altogether, replacing them with clearly documented test URLs that cannot be repurposed for malicious ends.
The report, originally published by Hackread, comes at a time when AI assistants are rapidly expanding into consumer and enterprise environments. As the functionality of these agents grows, so does the attack surface for threat actors seeking to exploit user trust. Ongoing monitoring and collaborative remediation efforts will be essential to prevent similar abuse from proliferating across the burgeoning AI skill marketplace.
Comments (0)
Be the first to comment.
Join the discussion