What was found
Manifold Security identified placeholder domains referenced in roughly 359,000 GitHub files and used by 349 AI agent skills. Some of those domains now redirect to scam pages.
Reported on 26 September 2026 by Deeba Ahmed at Hackread. Vulners rates it 5.7, medium.
Why a placeholder domain is a live problem
Example domains are written into code constantly - documentation, config templates, test fixtures, sample API endpoints. The convention is that they are obviously fake and nobody ever resolves them.
That convention only holds if the domain is genuinely unregisterable. example.com is reserved by IANA and always will be. A domain someone invented for a tutorial is not reserved - it is simply unregistered, which is a different thing entirely, and it is available to anyone with a card.
When an agent skill ships with one of those, whoever registers it decides what the skill connects to.
Why it matters more for agent skills than for ordinary code
A placeholder in a code sample waits for a human to notice and replace it. A placeholder inside an agent skill may be fetched automatically, because that is what skills do - they instruct an agent to go and get something.
Three differences from a normal dependency problem:
- No install step to review. Skills are often pulled at runtime. There is no package manifest anybody reads first.
- The agent has your credentials. Whatever the skill reaches is reached with the agent's environment - tokens, keys, network position.
- Nobody sees the response. A human visiting a scam page recognises it. An agent parsing the reply does not.
Check your own
For any agent skill or MCP server you have installed:
# Pull every domain referenced in your installed skills
grep -rhoE 'https?://[a-zA-Z0-9.-]+' ~/.claude/skills/ ~/.config/*/skills/ 2>/dev/null | sed -E 's|https?://||; s|/.*||' | sort -u
# Then for each one that is not a domain you recognise:
whois example-domain-here.com | grep -iE 'creation|registrar|no match'
"No match" means unregistered - anyone can take it. A creation date from the last few weeks on a domain your tooling has referenced for a year is the one to worry about.
What to do about it
- Pin your skills to a version and a commit. Runtime-fetched skills are the whole problem; a pinned copy you reviewed is not.
- Allowlist egress by domain. If the agent can only reach the four hosts it actually needs, a hijacked placeholder resolves to nothing. The same DNS allowlisting that closes the OpenAI-style escape closes this too - see how to sandbox an AI agent.
- Use reserved example domains when you write skills.
example.com, example.org, example.net and anything under .invalid or .test can never be registered by anyone. An invented domain can.
The pattern this month
This is Manifold Security's second agent supply-chain finding in four weeks, after GitSpawn showed a repository's own Git config can name a command the agent executes.
Both share a shape: the dangerous thing is not the model or the code, it is a piece of configuration that something else controls. Agent tooling has inherited every supply-chain weakness of package management and added runtime fetching on top of it.
FAQ
How many skills are affected?
349 AI agent skills, referencing placeholder domains found across roughly 359,000 GitHub files.
What happens if an attacker registers one?
They control what any skill referencing that domain connects to, with whatever credentials and network access the agent has.
Which domains are safe to use as placeholders?
example.com, example.org, example.net, and any name under the reserved .invalid, .test, .example or .localhost suffixes. These are reserved by standard and cannot be registered.
How serious is it?
Vulners rates it 5.7 - medium. The severity is limited by needing an attacker to register the right domain; the breadth is what makes it notable.