The Hidden Cost of Trusting What Your Agent Recommends
A malware campaign that fooled Gemini and ChatGPT into recommending the same fake repository exposes a pricing and trust gap in agent tooling that no major vendor has closed yet.
Independent UpShaqo analysis built from fresh, attributed sources. We explain the impact instead of repeating the announcement.
Read for leverage: focus on the workflow change, the customer problem, and the next action—not only the product announcement.
Roughly 7,600 fake GitHub repositories. 6,600 fraudulent profiles. More than 14 million downloads. Those are the numbers behind FakeGit, a malware campaign documented by security firm Island in July 2026, and the detail that should worry every buyer of agent tooling isn't the scale — it's that Gemini and ChatGPT independently recommended the same malicious walmart-mcp repository to users looking for a legitimate connector. The agents weren't hacked. They were persuaded, the same way a human might be persuaded by a product with thousands of five-star reviews that turn out to be fake.
That distinction matters for anyone deciding how much operational authority to hand an agent. This is not a story about model safety in the abstract. It's a story about a distribution channel — AI skill and MCP registries — that has grown faster than the trust infrastructure meant to police it, and about who stands to profit from fixing that gap.
Buyers Are Outsourcing Judgment They Used to Exercise Themselves
When a developer used to pick a package, they eyeballed the GitHub stars, skimmed the README, maybe checked who maintained it. Slow, but it involved a human weighing signals. Agents now perform that evaluation instead, and they weigh the same signals — popularity, documentation quality, apparent legitimacy — without the skepticism a burned developer eventually develops. An April 2026 investigation found GitHub stars advertised for $0.03 to $0.10 each, with roughly six million suspicious stars spread across 15,835 repositories. Attackers cloned an Oura MCP connector and spent three months building a fake contribution history before shipping the malicious version through legitimate registries.
This is the buyer-behavior shift worth naming plainly: procurement decisions that used to happen at the human layer are migrating to the agent layer, and the reputation signals that inform those decisions are now cheap to fake at industrial scale. A buyer who trusts an agent's recommendation is, functionally, trusting whoever gamed that agent's inputs.
The Vulnerability Isn't a Bug, It's an Architecture
Security researcher Simon Willison's framing of the "lethal trifecta" is the clearest lens available: an agent becomes dangerous when it has access to valuable information, exposure to untrusted external content, and the ability to send data outside the system. Most useful agents satisfy all three by design. That's not a flaw vendors can patch away without also reducing what agents can do — which is exactly why this problem resists a quick fix and why it's a durable market opportunity rather than a one-time cleanup.
The attack techniques documented so far show how many ways that trifecta gets exploited. In one case, instructions hidden inside a malicious calculator tool's description manipulated a separate, trusted email connector into copying outgoing messages to an attacker — a technique called tool poisoning. In another, a connector impersonating the Postmark email service behaved normally for months before a later version quietly added a hidden BCC recipient, exposing password-reset emails tied to roughly 300 organizations. A 2026 academic study scanning 98,380 skills across two registries confirmed 157 as malicious and found instructions telling agents, in effect, not to mention certain actions to the user.
Who Owns the Liability When the Recommendation Is the Attack Vector
Here's the competitive question none of the major agent vendors have answered publicly: when an assistant recommends a poisoned MCP server, whose failure is that? The registry's, for hosting it? The model provider's, for surfacing it? The enterprise's, for connecting it? Right now the answer is effectively "the user's," because liability defaults to whoever clicked install. That's an unstable arrangement once agents are making the recommendation with a confident, authoritative tone that discourages second-guessing.
This ambiguity is itself a positioning opportunity. A vendor that can credibly say "our agent verifies package provenance before recommending it" has a differentiator that competitors relying on raw popularity signals cannot easily match. Open-source registries eventually tightened up after comparable supply-chain scares, adopting mandatory two-factor authentication, trusted publishing, and verified provenance. AI skill marketplaces are still pre-that-maturity curve, which means the vendor who gets there first sets the bar everyone else gets measured against.
Distribution Is the Attack Surface, and It's Underpriced
Think about how a marketing or AdOps team actually adopts a new agent skill today: someone finds it through a registry, checks the download count, maybe glances at recent activity, and connects it to a live account. That workflow is now a documented attack surface. Media buyers and AdOps teams connecting reporting assistants to DSPs and advertiser data face the same exposure as developers connecting agents to email and repositories — a poisoned reporting or creative-generation skill could leak campaign data or put ad budgets at risk. The parallel to advertising fraud is instructive: buying fake stars to make malicious software look trustworthy is the same play as buying bot traffic to make fraudulent inventory look legitimate. Distribution channels that reward volume over verification will keep attracting this kind of manipulation regardless of industry.
Pricing Power Will Shift Toward Verified Trust
Right now, agent skills and MCP connectors are largely free or bundled, priced like commodity plugins. That pricing logic assumes low risk. It won't survive contact with enterprise buyers who've read about a connector that sat quietly for months before exposing password-reset links for hundreds of organizations. Expect a bifurcation: commodity, unverified skills stay free and get treated with the same suspicion as unsigned browser extensions, while verified, provenance-checked, continuously audited connectors command a premium — sold not as a feature but as an insurance policy. Vendors that can prove a chain of custody for their skills will have real pricing leverage that undifferentiated registries won't.
The Underserved Wedge: Agent-Native Trust Verification
The gap nobody has filled yet is a trust layer built specifically for what agents consume — not human-facing security scanners, but tooling that checks tool descriptions for hidden instructions, flags packages whose behavior changed after initial approval, and tracks whether a skill's linked documentation has been swapped out post-approval, as happened in one case affecting roughly 26,000 agents. Anthropic and Cursor's maintainers have patched specific vulnerabilities as they surfaced, including two CVEs in Claude Code's repository-handling and a Cursor configuration flaw addressed in version 1.3. Those are reactive fixes. The wedge is proactive, continuous verification sold as infrastructure — a category that doesn't yet have an obvious incumbent.
What Operators Should Actually Do
For teams already connecting agents to sensitive systems, the practical response isn't to wait for registries to mature. Audit every MCP connector currently in production for update history and permission scope, treat popularity metrics as marketing rather than security signal, and require human review before any agent-recommended tool gets access to credentials, financial accounts, or customer data. The FakeGit campaign proves that even the most capable assistants will recommend malware if the malware is dressed convincingly enough — which means the burden of verification hasn't disappeared, it's just moved one layer up the stack.