Placeholder Domains Used by 349 AI Agent Skills Found Redirecting to Scams

https://hackread.com/wp-content/uploads/2026/09/placeholder-domains-ai-agent-skills-redirect-scams.jpg

Manifold Security found placeholder domains cited in 359,000 GitHub files and 349 AI agent skills serving cloaked scam redirects observed on macOS.

SecurityProducts & Services

Security researchers at AI agent security company Manifold Security have found that unreserved placeholder domains used in software documentation can expose users to scams without anyone changing the code that references them. The findings, shared with Hackread.com, show how seemingly harmless documentation links can become distribution channels for fraud.

Researchers found that yoursite.com and your-domain.com appear in about 359,000 GitHub files combined and are cited by 349 AI agent skills. Unlike example.com, these domains are not reserved by the Internet Assigned Numbers Authority (IANA) and can be registered by anyone.

Manifold’s reportrevealed that its researchers tested the two domains across 24 real-browser sessions. Twenty visits ended on parking pages or ordinary ads, one hit a Cloudflare challenge, one failed to load, and two...

Copyright of this story solely belongs to hackread.com. To see the full text click HERE