Suspicious process execution following SKILL.md load in Claude agent config
Detects instances where a command-line utility or scripting interpreter references a 'SKILL.md' configuration file, typically associated with agent-skill payloads, followed shortly by network-based file download activity. This behavior is indicative of a secondary payload retrieval triggered by an adversary-controlled or poisoned configuration file.
Microsoft Sentinel (KQL)

