frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Show HN: Scanning 277 AI agent skills for security issues

https://www.clawdefend.com/
2•pakmania•2h ago

Comments

pakmania•2h ago
Six weeks ago I got curious what’s actually inside the AI agent “skills” people install from ClawHub, not the descriptions, but the source code.

So I built a scanner.

It pulls skill source from GitHub, runs a set of static analysis checks (shell execution patterns, environment variable access, hardcoded credentials, SSRF patterns, eval usage, basic obfuscation detection, etc.), and then runs a second pass using an LLM to classify whether the flagged pattern looks contextual vs. potentially risky.

So far I’ve scanned 277 public skills.

Some aggregate observations:

70% triggered at least one static rule

9,710 total findings across all scans

Common patterns included unsanitized shell execution and unrestricted environment variable reads

Important caveats:

Many findings are low severity.

Static analysis is noisy.

“70%” means at least one rule triggered — not that 70% are malicious.

No dynamic/runtime execution — this is source-based analysis only.

Binary-only skills are conservatively capped due to limited visibility.

The tool is live at clawdefend.com — you can paste any ClawHub or GitHub skill URL and get a report in ~30 seconds. No login required.

There’s also a simple API if you want to integrate scans into CI or publishing workflows.

Curious how others are thinking about security models for agent marketplaces. Is static + contextual classification reasonable here, or is there a better approach?

Solo project. Happy to go deeper on methodology.

openclawed•1h ago
This is interesting. I'm going to scan some of the skills I have installed and see if it finds any issues. We need reliable scanners for these skills.
pakmania•1h ago
Thanks, let me know what you think about the results and if you run into any issues. There's also a Contact & Support link at the bottom of the page.

Patterns in AI-Augmented Software Development

https://library.chironcodex.com/books/patterns-in-ai-augmented-software-development
1•grahamlee•38s ago•0 comments

The six dumbest ideas in computer security (2005)

https://www.ranum.com/security/computer_security/editorials/dumb/
1•alcazar•2m ago•0 comments

Google accelerates Chrome release cycle

https://www.theverge.com/tech/888001/google-accelerates-chrome-releases-cutting-cycle-in-half
2•cdrnsf•2m ago•0 comments

You are going to get priced out of the best AI coding tools

https://newsletter.danielpaleka.com/p/you-are-going-to-get-priced-out-of
1•fi-le•3m ago•0 comments

Helicone Is Joining Mintlify

https://www.helicone.ai/blog/joining-mintlify
1•mgw•4m ago•0 comments

Show HN: Letting Claude automate fleets of browser sandboxes

https://twitter.com/steeldotdev/status/2028855809233526799
1•huss97•5m ago•0 comments

The 5am myth: Waking early won't make you more successful

https://www.rnz.co.nz/life/wellbeing/the-5am-myth-waking-early-won-t-make-you-more-successful
5•billybuckwheat•6m ago•0 comments

GPT‑5.3 Instant

https://openai.com/index/gpt-5-3-instant/
1•meetpateltech•7m ago•0 comments

Show HN: Qgate – Classical trajectory filtering for noisy quantum circuits

https://github.com/ranbuch/qgate-trajectory-filter
1•ranbuch•8m ago•0 comments

Show HN: BaseCFO – workbooks as a queryable dashboard for fractional CFOs

https://basecfo.com:443/early-access
1•mustafabagdatli•9m ago•0 comments

Show HN: Viib – Generate production ready static ads from a single URL

https://viib.co
1•travelhead•9m ago•0 comments

1995: From Batman Forever's cinematic design to HTML tables

https://cybercultural.com/p/1995-web-design/
2•colinprince•10m ago•0 comments

Show HN: t-req – Open-source programmable API engine built on .http files

https://github.com/tensorix-labs/t-req
2•mad_poet•11m ago•0 comments

Lucent: YouTube Focus Mode and Auto 4K open source

https://chromewebstore.google.com/detail/lucent-youtube-focus-mode/bpciannhcoipobpfeofondnhiadfcbib
2•lvfrm•11m ago•0 comments

Show HN: MuninnDB – ACT-R decay and Hebbian memory for AI agents

https://github.com/scrypster/muninndb
2•mjbonanno•12m ago•2 comments

Microgpt on the ESP32 – But Why?

https://duggan.ie/posts/microgpt-on-the-esp32-but-why
2•duggan•12m ago•0 comments

Shattered Glass (1998)

https://www.vanityfair.com/magazine/1998/09/bissinger199809
2•thomassmith65•14m ago•1 comments

Upgrading the Samsung Trifold battery by 71% using SiC

https://www.youtube.com/watch?v=YCQLKhB2ywQ
2•luyu_wu•15m ago•0 comments

Ask HN: How do solo founders find academic co-founders for STTR grants?

2•Rao_Atreya•15m ago•1 comments

Would You Buy Generic AI?

https://tomtunguz.com/white-label-ai/
2•swolpers•15m ago•0 comments

Show HN: Arbor – AI research workbench, question to knowledge graph

https://www.arborinquiries.com/
2•FlynnLachendro•16m ago•1 comments

PEP 827 – Type Manipulation

https://peps.python.org/pep-0827/
3•pboulos•17m ago•0 comments

Regenerator 2000: interactive disassembler for the C64 and other 6502 systems

https://regenerator2000.readthedocs.io/en/latest/
3•homarp•17m ago•1 comments

CEOs are betting big on AI while barely using it

https://www.charterworks.com/ceos-are-betting-big-on-ai-while-barely-using-it/
5•swolpers•18m ago•0 comments

The AI Bubble Is an Information War

https://www.wheresyoured.at/the-ai-bubble-is-an-information-war/
5•spking•19m ago•0 comments

Google violates its 14-day deprecation policy for Gemini 3 Pro Preview

4•goolulusaurs•20m ago•0 comments

US Stock Market has lost $1 TRILLION in value since open Tuesday

https://old.reddit.com/r/StockMarket/comments/1rjtww8
5•ck2•21m ago•1 comments

A lightweight, embeddable Prolog interpreter written in C11

https://github.com/no382001/prolog
2•triska•24m ago•0 comments

Blackberry Growth Monitoring and Feature Quantification with UAV Remote Sensing

https://www.mdpi.com/2624-7402/6/4/260
2•PaulHoule•24m ago•0 comments

The Court's (Selective) Impatience Is a Vice

https://www.stevevladeck.com/p/214-the-courts-selective-impatience
3•hn_acker•24m ago•1 comments