AIR says its fake AI skill passed scanner checks by using a mutable external link, exposing a blind spot in agent skill ...