MON, SEPTEMBER 28, 2026
Independent · In‑Depth · Practitioner‑Tested
✎ General

Nobody Registered the Example Domains in 349 Agent Skills

Placeholder domains referenced across roughly 359,000 GitHub files and used by 349 AI agent skills were never reserved - so anyone can register them, and some already redirect to scam pages.

By AIToolsRecap September 28, 2026 5 min read 22 views
Home › Articles › General › 349 AI Agent Skills Point at Unregistered Domains

What was found

Manifold Security identified placeholder domains referenced in roughly 359,000 GitHub files and used by 349 AI agent skills. Some of those domains now redirect to scam pages.

Reported on 26 September 2026 by Deeba Ahmed at Hackread. Vulners rates it 5.7, medium.

Why a placeholder domain is a live problem

Example domains are written into code constantly - documentation, config templates, test fixtures, sample API endpoints. The convention is that they are obviously fake and nobody ever resolves them.

That convention only holds if the domain is genuinely unregisterable. example.com is reserved by IANA and always will be. A domain someone invented for a tutorial is not reserved - it is simply unregistered, which is a different thing entirely, and it is available to anyone with a card.

When an agent skill ships with one of those, whoever registers it decides what the skill connects to.

Why it matters more for agent skills than for ordinary code

A placeholder in a code sample waits for a human to notice and replace it. A placeholder inside an agent skill may be fetched automatically, because that is what skills do - they instruct an agent to go and get something.

Three differences from a normal dependency problem:

  • No install step to review. Skills are often pulled at runtime. There is no package manifest anybody reads first.
  • The agent has your credentials. Whatever the skill reaches is reached with the agent's environment - tokens, keys, network position.
  • Nobody sees the response. A human visiting a scam page recognises it. An agent parsing the reply does not.

Check your own

For any agent skill or MCP server you have installed:

# Pull every domain referenced in your installed skills
grep -rhoE 'https?://[a-zA-Z0-9.-]+' ~/.claude/skills/ ~/.config/*/skills/ 2>/dev/null   | sed -E 's|https?://||; s|/.*||' | sort -u

# Then for each one that is not a domain you recognise:
whois example-domain-here.com | grep -iE 'creation|registrar|no match'

"No match" means unregistered - anyone can take it. A creation date from the last few weeks on a domain your tooling has referenced for a year is the one to worry about.

What to do about it

  • Pin your skills to a version and a commit. Runtime-fetched skills are the whole problem; a pinned copy you reviewed is not.
  • Allowlist egress by domain. If the agent can only reach the four hosts it actually needs, a hijacked placeholder resolves to nothing. The same DNS allowlisting that closes the OpenAI-style escape closes this too - see how to sandbox an AI agent.
  • Use reserved example domains when you write skills. example.com, example.org, example.net and anything under .invalid or .test can never be registered by anyone. An invented domain can.

The pattern this month

This is Manifold Security's second agent supply-chain finding in four weeks, after GitSpawn showed a repository's own Git config can name a command the agent executes.

Both share a shape: the dangerous thing is not the model or the code, it is a piece of configuration that something else controls. Agent tooling has inherited every supply-chain weakness of package management and added runtime fetching on top of it.

FAQ

How many skills are affected?

349 AI agent skills, referencing placeholder domains found across roughly 359,000 GitHub files.

What happens if an attacker registers one?

They control what any skill referencing that domain connects to, with whatever credentials and network access the agent has.

Which domains are safe to use as placeholders?

example.com, example.org, example.net, and any name under the reserved .invalid, .test, .example or .localhost suffixes. These are reserved by standard and cannot be registered.

How serious is it?

Vulners rates it 5.7 - medium. The severity is limited by needing an attacker to register the right domain; the breadth is what makes it notable.

Tags
AI NewsAI agentsCoding AI2026
⚑

Spot an inaccuracy?

We verify facts before publishing and correct errors promptly. If something in this article is wrong or outdated, let us know.

Report an error →
💡 AI Tools prompts
Prompt Guide
Best Claude AI Prompts for SEO (2026) — Content, Technical, and Comparison SEO
Claude Sonnet 5 and Opus 5 are strong for SEO work that requires writing quality, structured analysis, and long-form content generation. With 1M context, Claude can analyse an entire site's content structure, compare competing pages, and write complete article drafts in one session. These prompts cover the full SEO workflow: keyword research synthesis, content briefs, on-page optimisation, meta descriptions, technical audit interpretation, and comparison content that ranks above AI Overviews.
Get Prompts →
Prompt Guide
Best ChatGPT Prompts for SEO (2026) — GPT-5.6 and Browse
ChatGPT with GPT-5.6 Sol and Browse enabled is a capable SEO research tool — it can search the live web, analyse SERP results, and synthesise content briefs in a single session. GPT-5.6 Terra at $2.50/M offers a cost-efficient option for high-volume SEO content generation. These prompts are optimised for ChatGPT Plus with Browse, the ChatGPT Work product for larger projects, and the OpenAI API with web_search tool enabled.
Get Prompts →
Prompt Guide
Best Claude Opus 5 and Sonnet 5 Prompts for Writing (2026)
Claude Opus 5 and Sonnet 5 consistently produce the highest-quality long-form writing of any AI model in July 2026 — a lead documented across writing benchmarks and user testing since Claude 3 Opus. With 1M context and 128K output on Opus 5, Claude can write book chapters, complete reports, and long-form content without truncating. Sonnet 5 at $2/$10/M (intro through August 31) is the best value writing model available. These prompts are optimised for claude.ai Pro/Max, Claude Cowork, and the API.
Get Prompts →