Capsule Security's analysis of AI agent infrastructure found 402,599 unique publicly reachable hosts across 36 services, most deployed without authentication or prompt injection guardrails. Analyzing 206,435 agent skill files and 164,692 code files across ~86,000 public repositories, researchers found AI workloads carry 14.6x more dependencies than indicated, making their supply chain attack surface 6x larger than comparable software. Top exposed services include OpenClaw, n8n, and Ollama. The majority of AI agent code is Python-based, inheriting that language's security weaknesses. One tracked malicious campaign continued propagating malicious skills into IDE plugins 10 weeks after its official termination. Security teams are urged to deploy their own agents to understand the risks, as broad compromise is considered inevitable rather than hypothetical.