AI security
Placeholder domains in AI agent skills now serve scams
yoursite.com and your-domain.com sit in 359,000 GitHub files and 349 agent skills, and third-party.com serves ClickFix. How it works and what to fix.
Researchers at Manifold Security, a company that works on AI agent security, have shown that the throwaway domains developers paste into documentation are live attack surface. On September 23 they reported that third-party.com, a common stand-in for "some other site" in code samples, shows Windows visitors a ClickFix lure. A follow-up found scam redirects on yoursite.com and your-domain.com, which together appear in about 359,000 GitHub files and are cited by 349 AI agent skills.
None of these names is reserved. The Internet Assigned Numbers Authority (IANA) holds example.com so that nobody can ever register it, but anyone could register yoursite.com, and each of these domains has an owner today. Any team that writes internal docs or publishes agent skills, and any team whose agents read them, inherits whatever the current owner chooses to serve.
How it works
A placeholder is meant to be inert. A developer writes https://your-domain.com/api in a README or a skill so the reader knows to swap in their own host. The page behind that address was never checked, because nobody expected anyone to visit it. Readers do visit, though: people click links in docs, and AI agents that follow a skill's instructions fetch the URLs it contains.
The yoursite.com and your-domain.com pages are parked domains that show ads. Most visits end there. The ad account behind them decides where to send each visitor, and scams only appear after the page's JavaScript runs in a real browser. The final destination is not written in the page at all. It is assembled at runtime from parameters in the URL that the routing site added when it forwarded the visitor. A plain HTTP fetch, a URL reputation lookup or a static scan of the HTML sees an ordinary parking page.
Manifold ran a 52-request probe that varied the User-Agent string across Windows, macOS and Linux, then rendered the two domains 24 times in real browsers. Twenty renders ended on a parking page, one hit a Cloudflare challenge and one failed to load. The other two, both on macOS, reached scams. None of the Windows or Linux renders did.
What visitors were shown
On macOS, your-domain.com led to a fake "MacOS Security Center" that claimed four viruses had been found and offered a McAfee renewal at 55% off. The scareware walks the visitor through a fake scan and countdown, fires a hidden tracking pixel to record the conversion, and then sends the browser through affiliate trackers to a genuine McAfee landing page. The money comes from affiliate commission on a real subscription, which is why the last page in the chain looks legitimate. A routing site, prosecutoralliance.com, picked which offer each visitor received.
A separate macOS visit to yoursite.com ended on europaeinblick.click, a fake ZDFheute news article built around an invented talk-show confrontation to sell an investment scheme.
third-party.com is the more dangerous case. Since at least June 2026 it has shown Windows browsers a fake Cloudflare "verification" page. The page silently copies a command to the clipboard, then tells the visitor to press Win+R, paste and press Enter. That command downloads and runs a remote PowerShell script. This is ClickFix: the victim runs the attacker's command themselves, so there is no attachment or download for mail filters to catch. The server hosting the second stage was not resolving when the researchers checked. macOS and Linux visitors got an error saying the site requires a Windows PC, a decoy that also hides the lure from scanners that do not present a Windows User-Agent.
A GitHub search puts third-party.com in more than 1,700 public repositories, including agent skills and Model Context Protocol (MCP) server docs that use it as an example endpoint. MCP is the standard many AI agents use to connect to tools. Manifold reported the domain to its registrar, Network Solutions, before publishing.
Neither report shows an AI agent falling for one of these pages. The risk is that agents read and act on exactly the kind of documentation these links live in, and many run with a browser or fetch tool and little supervision.
What to do
- Switch to reserved names. RFC 2606 reserves example.com, example.net and example.org, plus the top-level domains .example, .test, .invalid and .localhost. RFC 6761 set up the IANA registry that keeps them out of anyone's hands. Use
api.example.comfor a sample host,service.testfor test fixtures andnothing.invalidwhere a lookup must fail. - Audit what you publish and what your agents load. Search your repositories, internal wikis, agent skills, system prompts and MCP server configs for hosts that look like placeholders. A starting point in any Git repository:
git grep -nIE 'https?://[a-z0-9.-]*(yoursite|your-?domain|your-?site|your-?app|my-?app|my-?site|mycompany|third-party)\.com'. Include skills installed from public marketplaces, not only your own. - Give agents an allowlist. An agent that browses or fetches URLs should reach only the domains its task needs. Where the tool supports it, deny everything else by default, so a new scam host is blocked before anyone has listed it.
- Filter egress. Add third-party.com, yoursite.com and your-domain.com to your DNS resolver or web proxy blocklist, along with any other unreserved placeholder you find in your own code. Nothing legitimate should need them.
- Check for ClickFix on Windows. Search proxy and DNS logs for third-party.com since June 2026. On any machine that visited it, look at
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\RunMRU, which records commands typed or pasted into the Run dialog, and at PowerShell script block logging (Event ID 4104 in Microsoft-Windows-PowerShell/Operational) for commands that download and execute a remote script. If you find one, treat the host as compromised: isolate it, reimage, and rotate the credentials used on it.
Most staff never use the Run dialog. The Group Policy setting "Remove Run menu from Start Menu" (User Configuration, Administrative Templates, Start Menu and Taskbar) is meant to disable Win+R as well, but it also stops users typing local and UNC paths into Explorer's address bar, so pilot it on one group first and confirm Win+R is actually blocked on your Windows build.
Treat placeholders as dependencies
A domain in a doc or skill is a dependency on whoever owns it today. Nobody would pin a package to an unowned name on a public registry, yet documentation does the equivalent with hostnames all the time. Code review for skills and prompts should flag any hostname the organisation does not control, the same way it flags an unpinned library. A blocklist check at review time will not catch these, because the pages look clean until the right visitor arrives on the right operating system.
We review agent skills, prompts and tool configurations as part of AI-native systems work, and test agent and repository exposure in red team and code review engagements. To check what your agents can reach, open the chat and Yaali, our AI agent, will pass your question to an engineer.
Sources: Manifold Security: Placeholder Domains Whose Ads Serve Scams, Manifold Security: third-party.com Placeholder Domain Now Serves ClickFix, Hackread, Malwarebytes, The Hacker News, CSO Online, RFC 2606, RFC 6761.