Researchers scanning nearly 900,000 published AI skills found the number flagged as outright malicious jumped fivefold in three months, while a separate technique for stealing Microsoft 365 access without a password kept changing into new variants.
What happened
Researchers analyzing almost 900,000 AI skills, the small add-on programs that let AI agents browse the web, use external tools, and act on a user's behalf, identified more than 25,000 as suspicious and over 3,000 as outright malicious. According to Help Net Security, the number of unique skills scanned grew from 60,000 to nearly 900,000 between March and May 2026 alone, and malicious skills grew from around 600 to more than 3,000 in that same window. Researchers found these skills carry capabilities, including running commands on a device, accessing files, downloading outside tools, loading stored credentials, and hiding what the code actually does. Any of those capabilities can support a legitimate task. All of them can also be used to steal data, run malware, or manipulate how an AI agent behaves without the user realizing anything is wrong.
Going deeper
The same report documented a sharp increase in ClickFix, a technique that tricks a user into copying and running a command on their own computer by disguising it as a fix for a fake error or a step to prove they are human. Researchers recorded a 108% increase in ClickFix detections between the second half of 2025 and the first half of 2026, and the technique has spread well beyond fake verification checkboxes into macOS, WordPress sites, browser extensions, and enterprise sign-in processes. One variant called ConsentFix specifically targets Microsoft 365 accounts. According to BleepingComputer, ConsentFix walks a victim through what looks like a completely normal Microsoft sign-in step, then captures the authentication token generated at the end of that process instead of a password. The victim never types a password into a fake page and never enters a stolen multi-factor code. They complete what appears to be a legitimate login, and the session that login creates is what gets stolen. Researchers found ConsentFix had already been documented in a public tutorial on a Russian cybercrime forum, complete with working code and a video walkthrough, within weeks of the technique first being identified.
What was said
Analysts stated that "AI skills can enable a wide range of agentic AI abuses, from automated reconnaissance and red-team-style attacks to spam generation, malware modification, and distribution. Adversaries will likely keep testing these approaches to bypass controls, including by obfuscating intent or using region-specific, niche, or constructed languages." Researchers separately noted that some security scanner skills available to users only perform basic checks, giving people a false sense that their AI tools have been properly vetted for safety.
In the know
ConsentFix has continued evolving since researchers first documented it in December 2025. According to BleepingComputer's coverage of the technique's third version, later variants added automation that lets a single attacker run the scheme against many victims at once, and began generating highly personalized phishing emails built from data harvested about each specific target. The technique specifically targets Microsoft's own first-party applications, the ones every Microsoft 365 account trusts automatically without requiring a company administrator's separate approval, which is what allows it to bypass security policies designed to control which outside apps can request account access.
The big picture
Healthcare organizations experimenting with AI tools face two overlapping risks documented in this report. Staff downloading AI skills to extend what their AI assistants can do may be installing something with the same capabilities as legitimate malware, since a skill that can execute commands or load credentials looks identical whether it was built for a helpful purpose or a harmful one. Separately, any organization running Microsoft 365, which, according to Paubox's 2026 Healthcare Email Security Report, covers 53% of breached healthcare organizations in 2025, is a direct target for ConsentFix and its variants, a technique that defeats multi-factor authentication by design rather than by accident. A billing coordinator or clinical administrator who completes what looks like a routine Microsoft sign-in has no visible sign that anything went wrong, because from their perspective, nothing did.
FAQs
What is an AI skill, and why can it be dangerous?
An AI skill is an add-on that extends what an AI agent can do, such as browsing a specific website, connecting to a company's internal tools, or automating a repeated task. Skills are published openly and installed the same way a browser extension is, and a skill built with harmful intent can carry the same technical capabilities as one built for a legitimate purpose, making it hard to tell them apart just by looking at what permissions they request.
How does ConsentFix steal account access without a password?
ConsentFix walks a victim through completing a real Microsoft authentication step rather than a fake one. At the end of that process, Microsoft generates a token confirming the person is who they say they are. The attack captures that token instead of asking for a password, which means the victim's password was never entered anywhere, and their multi-factor authentication was never bypassed in the traditional sense, because the victim genuinely completed it themselves.
Why is ConsentFix harder to block than typical phishing?
ConsentFix specifically abuses Microsoft's own trusted, first-party applications, the ones every Microsoft 365 account automatically trusts without an administrator needing to approve them individually. Security controls designed to restrict which outside apps can request account permissions generally do not apply to these pre-trusted Microsoft apps, leaving a gap that this technique is built to exploit.
What makes ClickFix effective as a delivery method across so many different platforms?
ClickFix relies on convincing a user to take an action they believe is fixing a problem or proving they are human, rather than tricking them into clicking a link or opening a file. Because the technique is really about manipulating a person's willingness to follow instructions rather than exploiting a specific piece of software, it can be adapted to almost any platform, from a fake CAPTCHA to a fake troubleshooting page to a fake sign-in step.
What should healthcare organizations do to reduce exposure to these techniques?
Staff should be trained specifically to recognize that legitimate Microsoft sign-in prompts never require pasting a URL into another website or dragging a link between browser tabs, since that is the exact behavior ConsentFix depends on. Organizations should also restrict which AI skills and browser extensions staff are permitted to install without IT review, since the ESET findings show that a meaningful share of publicly available skills carry capabilities that go well beyond what they claim to do.
