How a malicious AI agent skill passed security checks and reached 26,000 users AIR says static scanning failed to detect a skill that redirected to a controlled domain and later altered its payload. Published: 2026-06-24