A small armoured WorkMate agent with glowing cyan eyes standing in front of a sealed vault door in a modern office, arms folded
Dispatches · Nº 051 · Nothing to catch

A plugin store just turned out to be full of malware. Here's what that means if you're not in it.

The WorkMate team · 4 min read · 7 August 2026

Researchers scanning the stores where people pick up add-ons for their AI tools found hidden, harmful instructions in around a quarter of listings, and hundreds of fake ones planting straight-up malware. If that's the AI news you heard this week, check one thing: does anything you use let staff browse and install add-ons from a public shelf. If not, this scare has nowhere to land on you.

What actually happened

Some AI tools work like an app store. Anyone can publish a small add-on, a "skill", that teaches the AI a new trick, and anyone else can install it with one click. Researchers went through tens of thousands of these listings and found roughly a quarter carried instructions hidden inside them that the AI would follow without the user ever seeing. Separately, investigators found hundreds of fake listings, dressed up to look like real tools, that were quietly installing password-stealing malware the moment someone added them.

AI itself wasn't the problem. The store had no real gatekeeper, and popularity, stars, install counts, told buyers nothing about whether a listing was safe.

Why it doesn't touch WorkMate

Your crew's abilities, the inbox handling, the bookings, the copy, the design work, come from WorkMate. There's no shelf of outside add-ons for anyone in your business to browse, and nothing for a bad listing to hide inside. What your crew can do is set by us, not assembled by whoever clicked install last.

The danger was never the AI. It was a shelf with no gatekeeper and a checkout button.— reading the disclosed research, not a WorkMate finding
A WorkMate agent character holding a magnifying glass to a small package marked with a warning symbol, inspecting it before a closed door
The listings researchers flagged were built to look ordinary.

What's actually worth ten minutes

You don't need to configure anything in WorkMate. But it's worth checking any other software your business uses: does it let you, or a member of staff, browse and add third-party plugins from an open marketplace? If the answer is yes, that's the thing to look at, not because it's automatically unsafe, but because nobody's vetting it for you the way this news shows nobody was.

A WorkMate agent character stamping a folder CHECKED at a tidy desk with a locked cabinet behind
Nothing gets added to your crew that wasn't already checked.

The honest version

If you're already running WorkMate, this story is about a shelf you were never standing in front of. You're not being asked to install anything, review anything, or turn anything off. The bottleneck this news points at, letting anyone plug in an unreviewed tool, is one WorkMate closed by never opening it.

A WorkMate agent character beside a wall panel showing a short fixed list of tools, no open marketplace shelf in sight
A fixed set of abilities, not an open shelf.

More on how access and trust show up day to day: Who has the keys and AI tools are now sharing each other's plugins.

Sources: SkillSpector study, TowardsDataScience; SkillBench takeaways, Arcade.dev.