Skip to main content
Security & Compliance6 min read

Malicious AI Add-Ons Were Downloaded 1.7M Times

August 8, 2026By ChatGPT.ca Team

Here is a number worth sitting with. Security researchers recently disclosed that malicious skills uploaded to an AI agent marketplace racked up more than 1.7 million downloads in about three weeks. Skills are the little add-ons that extend what an AI agent can do, and people install them the way they install a browser extension: one click, no ceremony. That is the whole problem. The add-ons you bolt onto your AI are a software supply chain, and most businesses are not treating them like one.

Why the blast radius is bigger here

A sketchy phone app is mostly stuck in its own sandbox. An AI skill is not. It plugs into an assistant that may already be connected to your inbox, your documents, your customer records, and your business tools, and that can take actions on your behalf. So a malicious add-on does not merely misbehave in its own corner. It can potentially inherit the reach of the AI it extends. The one-click install habit we all developed for harmless browser extensions is badly mismatched to software that sits this close to the centre of your operations.

The habit that needs to change

Most of the risk here comes from treating add-ons as features rather than as installed software from a third party. Shifting that one mental model fixes most of it.

The one-click habitThe supply-chain habit
Install whatever looks usefulCheck who made it and whether they are real
Trust a big download countRemember download counts can be manufactured
Accept whatever access it requestsGrant the minimum the job requires
Leave it installed foreverRemove what nobody actually uses

This is the shadow side of the ecosystem we welcomed in the app store for AI agents. Assembling from ready-made parts is still the right strategy. It just means your parts list is now something you have to manage, much like knowing whose AI is inside your software.

Five minutes that cover most of the risk

You do not need a security program for this. Start with an inventory: what add-ons, plugins, connectors, and skills are actually installed across your AI tools, and who put them there? Most businesses find at least one nobody remembers approving, which is the same discovery problem as not knowing how many agents you are running. Then prune ruthlessly, because an unused add-on is pure risk with zero benefit. For what remains, check the maker is identifiable and credible, and confirm the access it holds is the minimum its job requires.

Keep the upside, drop the exposure

None of this argues for avoiding AI marketplaces. They are exactly why a small business can assemble genuinely capable AI without building anything, and the overwhelming majority of add-ons are legitimate and useful. What this incident shows is the familiar pattern where convenience arrives before governance. The fix is to apply the instinct you already have for anyone who gets keys to your building: know who they are, give them only what they need, and keep a list. Pair that with the vetting habits in our AI security buyer’s checklist and you keep the speed of the ecosystem without inheriting its worst risk.

Frequently Asked Questions

What actually happened?

Security researchers disclosed a supply chain campaign in which malicious skills were uploaded to an AI agent skills marketplace and accumulated more than 1.7 million downloads over roughly three weeks in mid-2026. Skills are small add-ons that extend what an AI agent can do, and people install them the way they would install a browser extension or a phone app. The scale is the point: this was not one unlucky business clicking the wrong link. It was over a million installs of tainted components into working AI setups, which tells you the distribution channel itself has become a target.

What is an AI "skill" and do I have any?

A skill is a packaged add-on that gives an AI assistant or agent a new capability, connecting it to a tool, teaching it a workflow, letting it perform a specific job. If you or anyone on your team has installed an extension, plugin, connector, or skill to make an AI tool do something extra, you have them. Many businesses do without thinking of it as installing software, because it takes one click and feels like a feature rather than a download. That casualness is exactly what makes this risk easy to miss.

Why is this different from a normal app store risk?

Because of what a skill gets access to. A dodgy phone app is limited to its own sandbox and whatever permissions you granted. An AI skill plugs into an assistant that may already reach your email, files, customer records, and connected business systems, and that can act on them. So a malicious add-on does not just misbehave in its own corner; it can potentially borrow the reach of the AI it extends. The blast radius is bigger, which means the vetting standard has to be higher than the one-click habit most people have developed.

How do I protect my business?

Treat AI add-ons as software you are installing, not features you are enabling. Know what is installed and who installed it, so you are not discovering skills you never approved. Prefer add-ons from credible, identifiable makers over anonymous ones with impressive download counts, since downloads can be manufactured. Check what access each one asks for and refuse anything that wants more than its job requires. Remove add-ons nobody uses, because unused software is pure risk. And keep a human approving consequential actions, so a compromised skill cannot quietly act on its own.

Does this mean we should avoid AI marketplaces?

No, and avoiding them would cost you real value. Marketplaces are why small businesses can assemble capable AI without building anything, and most add-ons are fine. The lesson is that convenience arrived before governance, as it usually does. Apply the same instinct you would to any supplier who gets keys to your building: check who they are, give them the minimum access needed, and keep a record of who has what. Do that, and you keep the upside of a fast-moving ecosystem without inheriting its worst downside.

Know exactly what your AI is running

We help Canadian businesses inventory and vet every AI tool, plugin, and skill in use, tighten permissions, and keep the parts list clean as you grow.

Related Articles

Security & Compliance

Prompt Injection: The AI Risk You Have Not Heard Of

August 6, 2026Read more →
Security & Compliance

New Rules for Labeling AI Content Arrive This Fall

August 3, 2026Read more →
Security & Compliance

The Industry Just Wrote You an AI Security Checklist

August 3, 2026Read more →
AI
ChatGPT.ca Team

AI consultants with 100+ custom GPT builds and automation projects for 50+ Canadian businesses across 20+ industries. Based in Markham, Ontario. PIPEDA-compliant solutions.

Stay ahead of AI in Canada

Weekly case studies, new tools, and ROI playbooks for Canadian SMEs. One email, zero spam.