
Eight popular scanners already missed it. Here's what actually catches a malicious AI agent skill before it reaches production — built for ASEAN engineering teams shipping fast under real compliance deadlines.
Your AI coding agent didn't get compromised by a sophisticated exploit. It got compromised by a marketplace skill with a convincing name and a polished README. The attack surface is hiding in plain sight — and your static scanner is likely missing it.

Popular static tools failed against basic obfuscation in controlled tests
This checklist takes thirty minutes — before any skill touches production
MAS, BNM, and OJK auditors will ask these questions — answer them first
Marketplace skills for AI agents are proliferating faster than security teams can review them. The problem isn't a lack of tooling — it's that existing tools weren't built for this threat model.
This isn't a US-centric compliance template retrofitted for the region. Ewashi built this checklist specifically for engineering and security teams operating under MAS TRM, BNM RMiT, and OJK POJK 11 frameworks — where moving fast and staying compliant aren't optional trade-offs.
Does this skill request access it shouldn't need? Identify over-permissioned agents before they reach your environment.
Who actually published this skill? Verify maintainer identity, commit history, and dependency chain integrity.
Dynamic checks that catch obfuscated payloads and unexpected network calls static scanners routinely miss.
The exact questions your MAS, BNM, or OJK auditor will eventually ask — answered before they arrive.

Static analysis targets known signatures. AI agent skills are contextually malicious — dangerous only when executed with your credentials and data access, making them invisible to traditional scanners.
Base64 or dynamic imports hide malicious logic from signature checks.
Payloads triggered by time delays or specific conditions bypass sandbox testing.
Compromised upstream packages inherit trust from the legitimate parent skill.

Regulatory timelines are accelerating. Engineering teams that treat compliance as a post-launch concern are inheriting audit risk that could have been resolved in thirty minutes at install time.
Ewashi runs adversarial assessments for mid-market engineering and security teams across Singapore, Malaysia, and Indonesia. We specialise in the gaps between what your existing tooling covers and what your actual threat surface looks like — including everything your AI agents can already reach.
While you wait — if you want a second set of eyes on what your AI agents can already reach, Ewashi runs adversarial assessments built for exactly this gap. Most mid-market teams are surprised by what we find in the first session.

Before You Install That AI Skill, Run This Checklist