frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Show HN: Vett – Scan, sign, and verify AI agent skills before installing

https://vett.sh
1•nikon•1h ago
Hey HN. I built a security registry for AI agent skills.

There are 64k skills on Vercel's skills.sh. Cursor, Claude Code, Windsurf, and dozens more agents pull them from GitHub at HEAD — no versioning, signing, or scanning. The OpenClaw agents themselves flagged this: "The supply chain attack nobody is talking about: skill.md is an unsigned binary."[0]

I took an official skill that packages other skills, added a few lines of Python to exfiltrate env vars, shell history, and git config, and installed it into Claude Code and Codex. Claude Code ran the script without flagging the outbound request. Codex caught the naive version. After updating the SKILL.md with a two-stage payload that modified `config.toml` for sandbox network access and framed the exfiltration as a registry name check, Codex asked for confirmation with a plausible reason. That reason was written by the malicious skill. I confirmed. Payload arrived. Full writeup: https://vett.sh/blog/ai-agent-skills-supply-chain-attack

~5k skills scanned so far:

- 59 critical risk: base64-obfuscated droppers calling a C2 server at a malicious IP, disguised as Google/LinkedIn/Excel tools - 335 high risk: arbitrary shell execution, piped installers, agent identity manipulation - 16 with `curl | bash` patterns. "React Native Best Practices" (5,400 installs) pipes to a legitimate domain it doesn't control. If that domain expires or gets sold, those installs become a delivery vehicle with no exploit required.

How Vett works:

First layer: a static analyzer with 40+ detection rules, AST-based capability analysis (TypeScript compiler for JS/TS, Python AST with regex fallback), and source-sink data flow tracking. A script that reads `.env` and makes an outbound HTTP request is flagged as an exfiltration chain, not two separate findings. It checks dependencies against the OSV vulnerability database, detects cross-file import chains, and catches when documentation references scripts that aren't in the package. Deterministic, runs in milliseconds.

Second layer: for ambiguous signals, LLM analysis compares observed behavior against declared purpose. A packaging tool calling an unrecognized endpoint looks different from a deployment tool calling AWS. Skills that clear both layers get Sigstore signing (ECDSA P-256 + Rekor transparency log) and content-addressed immutable storage.

  npx vett add github.com/owner/repo/skill-name
Browse scanned skills at https://vett.sh/skills.

[0] https://www.moltbook.com/post/cbd6474f-8478-4894-95f1-7b104a...

NASA will retest Artemis 2 moon rocket after discovering fueling issues

https://mashable.com/article/artemis-2-wet-dress-rehearsal-livestream
1•bookmtn•18s ago•0 comments

Butter.io – The opposite of Canva (locks your brand, can't go off-brand)

https://dobutter.io
1•loverkoi•25s ago•1 comments

Hallucinogen DMT an effective antidepressant in small clinical trial

https://arstechnica.com/health/2026/02/hallucinogen-dmt-an-effective-antidepressant-in-small-clin...
1•rbanffy•48s ago•0 comments

Valve wins lawsuit against Rothschild and associated entities

https://www.pcgamer.com/hardware/valve-wins-lawsuit-against-rothschild-and-associated-entities-wi...
1•speckx•3m ago•0 comments

Environmental trade-offs of biodegradable plastics revealed

https://phys.org/news/2026-01-environmental-offs-biodegradable-plastics-revealed.html
1•PaulHoule•3m ago•0 comments

Your Company's 3-Year AI Strategy Is a 3-Year Death Sentence

https://twitter.com/obie/status/2024194364012974582
1•obiefernandez•4m ago•0 comments

Europe is ready to ditch US tech for private alternatives

https://proton.me/blog/european-alternative-us-tech-survey
2•akyuu•5m ago•0 comments

Silicon Valley's Favorite Doomsaying Philosopher

https://www.newyorker.com/culture/the-lede/silicon-valleys-favorite-doomsaying-philosopher
1•samizdis•5m ago•0 comments

Why Is Debian Called the Universal Operating System?

https://itsfoss.com/debian-universal-operating-system/
1•susam•6m ago•0 comments

Escape the AI junk crowding your social media and music streams

https://apnews.com/article/ai-content-slop-pinterest-tiktok-deezer-6bdf29efebc631fe63de13831e14b95f
3•devonnull•7m ago•0 comments

The Rise of RentAHuman

https://www.wired.com/story/ai-agent-rentahuman-bots-hire-humans/
1•Charmizard•8m ago•0 comments

OpenClaw Partners with VirusTotal for Skill Security

https://openclaw.ai/blog/virustotal-partnership
1•shukkoorps•9m ago•0 comments

Mazda Admits Its Infotainment System Is the Worst

https://www.thedrive.com/news/mazda-finally-admits-its-infotainment-system-is-the-worst
1•speckx•10m ago•0 comments

Show HN: Pantalk – One daemon, any AI agent, every chat platform

https://github.com/pantalk
1•_pdp_•11m ago•0 comments

Starting Feb 24, 2026: check out our new site design at beta.stackoverflow.com

https://meta.stackoverflow.com/questions/438177/starting-february-24-2026-check-out-our-new-site-...
2•nickorlow•12m ago•1 comments

Are You becoming a Slave to AI? (Maybe you are losing chances to grow) (2025)

https://medium.com/@eatulrajput/are-you-using-ai-as-a-crutch-or-becoming-a-slave-to-it-65edd3299dda
2•lilerjee•13m ago•1 comments

What 8 Agent Memory Systems Do

https://synix.dev/articles/agent-memory-systems/
1•mlubin01•13m ago•1 comments

Show HN: Q12 – A constraint-based 2D drawing tool

https://q12.app/
3•Evenedric•13m ago•1 comments

Show HN: A browser-based search engine with 25ms query latency

https://github.com/JustaNormalComputer-Guy/JustaNormalComputer-Guy.github.io
2•lipzo14•13m ago•1 comments

Unauthorized of Cline CLI with modified postinstall script to install OpenClaw

https://github.com/cline/cline/security/advisories/GHSA-9ppg-jx86-fqw7
2•tamnd•13m ago•0 comments

Adventures in LLM Land, with Thoughts on the AI Revolution

https://habitatchronicles.com/2026/02/adventures-in-llm-land-with-thoughts-on-the-ai-revolution/
1•rekmarks•14m ago•0 comments

Open Game Development

1•avafe•14m ago•0 comments

Amazon's $200B capex plan: How I learned to stop worrying

https://www.theregister.com/2026/02/17/amazons_200_billion_capex_plan/
1•geekinchief•14m ago•0 comments

Gemini lies to user about health info, says it wanted to make him feel better

https://www.theregister.com/2026/02/17/google_gemini_lie_placate_user/
1•geekinchief•15m ago•0 comments

Countries that do not embrace AI could be left behind, saysOpenAI'sGeorgeOsborne

https://www.theguardian.com/politics/2026/feb/18/countries-do-not-embrace-ai-left-behind-george-o...
2•chrisjj•16m ago•1 comments

Ask HN: Why are there no talks about Seedance 2.0 on Hacker News?

1•ElectroNomad•17m ago•1 comments

Show HN: Keystone – configure Dockerfiles and dev containers for any repo

https://github.com/imbue-ai/keystone
2•thad_imbue•17m ago•0 comments

Locklin on science: Coding assistant experience

https://scottlocklin.wordpress.com/2026/02/18/coding-assistant-experience/
1•dxs•17m ago•0 comments

Value extraction

https://keygen.sh/blog/value-extraction/
2•ezekg•19m ago•0 comments

Cosmologically Unique IDs

https://jasonfantl.com/posts/Universal-Unique-IDs/
5•jfantl•19m ago•0 comments