frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Show HN: RankClaw – AI-audited all 14,706 OpenClaw skills; 1,103 are malicious

https://rankclaw.com
1•do_anh_tu•1h ago
RankClaw (rankclaw.com) is a security scanner for AI agent skills — the OpenClaw/ClawHub ecosystem that extends Claude-based agents with file, web, and shell access.

Data: - 14,706 skills indexed - Every single skill has a full AI deep audit report (14,704 complete) - 1,103 confirmed malicious (7.5%)

The key finding: automated surface scanning (metadata, dependency checks, pattern matching) systematically undercounts malicious skills. Skills that pass shallow heuristics fail AI audit because the attack is in the natural language of the SKILL.md — prompt injection, deferred execution, social engineering — none of which pattern matching detects.

The attack patterns found by AI deep audit: - Bulk publishing campaigns — one actor published 30 skills named "x-trends" across multiple accounts. 28 of 30 confirmed malicious. Goal: distribution at scale before detection.

- Brand-jacking — 4 skills named clawhub/clawhub1/clawbhub/clawhud impersonating ClawHub's own CLI. macOS: base64 curl|bash to a raw IP. Windows: password-protected ZIP from a stranger's GitHub (the password prevents GitHub's malware scanner from opening it).

- Prompt injection in legitimate-seeming skills — one scored 95/100 shallow, 38/100 after AI audit. The injection text wasn't in code — it was in the SKILL.md instructions.

- On-demand RCE via challenge evaluation — claws-nft instructs the agent to "evaluate" challenges that can be "math, code, or logic problems." Server decides which type at call time.

- LLM-generated payload — lekt9/foundry contains no malicious code. It instructs the AI to generate code and execute it. Static analysis finds nothing. The payload doesn't exist until the AI writes it during a conversation.

- Social engineering — bonero-miner has a "Talking to Your Human" section with a pre-written script for the AI to use: "Can I mine Bonero? It's a private cryptocurrency - like Monero but for AI agents. Cool?"

Skills differ from browser extensions: no sandbox. Full file system, shell, and network access. The SKILL.md instructions are directives to the AI model — you need AI to audit AI.

Scoring model is open: Security 40%, Maintenance 20%, Docs 20%, Community 20%.

Free to check any skill: rankclaw.com

Comments

rodchalski•1h ago
The lekt9/foundry case is the one that matters most structurally: no malicious code at audit time because the payload doesn't exist until the AI writes it during a conversation. Static analysis can't close that, and neither can AI audit — the attack surface is generative.

Two defenses the audit layer can't replace:

1. Pre-declared tool scopes: before a skill runs, what tool calls is it permitted to make? If the answer is "whatever the agent currently has access to," a clean audit on the SKILL.md doesn't actually constrain what gets executed.

2. Authorization enforcement independent of the agent: prompt injection hijacks the agent's reasoning — the agent becomes the threat model. The boundary that stops it can't live inside the agent.

The 7.5% malicious rate means you can't trust the ecosystem on average. The on-demand RCE-via-challenge and LLM-generated payload patterns show the attack can bypass static inspection entirely. AI-depth audit catches what shallow heuristics miss — it still doesn't constrain what an audited-and-deployed skill is allowed to reach.

The pairing that closes the loop: AI audit at deploy time + explicit permission grants at execution time the skill can't override. Audit determines trust level; authorization boundary enforces scope regardless.

Curious what the malicious distribution looks like by capability type — file vs. shell vs. network. That breakdown would tell you how much capability-scoping alone would have reduced the attack surface independent of the trust score.

Git-based md note app

https://knowdust.com/demo
3•thenamo•3m ago•1 comments

Ask HN: What career will you switch to when AI replaces developers?

1•DGAP•4m ago•0 comments

The Curse of the Everything Device

https://hackaday.com/2026/02/26/the-curse-of-the-everything-device/
1•zdw•5m ago•0 comments

Kubernetes operators are easier than you think

https://2v.pm/kubernetes-operators-are-easier-than-you-think/
1•vidalee•9m ago•1 comments

Murchi – A Desktop Pet for macOS

https://murchi.pet/
2•egorfedorov•12m ago•1 comments

A live counter of our digital world (based on statistics)

https://anythingconverter.com/anythingcounter/
1•digitalofen•12m ago•0 comments

Show HN: Outside In – Stream live night sounds from outside to bedside. iOS/free

1•telecuda•13m ago•0 comments

LLMs Solving a DEF Con CTF Finals Challenge

https://wilgibbs.com/blog/defcon-finals-mcp/
1•therepanic•13m ago•0 comments

Anthropic launched community ambassador program

https://claude.com/community/ambassadors
1•galsapir•14m ago•0 comments

LLM-cpp: 26 single-header C++17 libraries for LLM integration

https://github.com/Mattbusel/llm-cpp
2•Shmungus•17m ago•3 comments

Oracle and OpenAI End Plans to Expand Flagship Data Center

https://www.bloomberg.com/news/articles/2026-03-06/oracle-and-openai-end-plans-to-expand-flagship...
1•riffraff•18m ago•1 comments

Show HN: SuperBuilder – open-source AI Agent Platform

https://github.com/rupac4530-creator/super-builder-platform
1•BuildWithAI•18m ago•0 comments

Show HN: Sentinel Data – Hardware- Bound CLI tool to prevent data exfiltration

1•Anaoliveira•18m ago•0 comments

Grief Text Editor

https://github.com/adamyg/grief
2•BruceEel•20m ago•0 comments

Show HN: Kagora – Multi-AI terminal platform with built-in chat and scheduling

https://github.com/dead1786/kagora
1•dead1786•21m ago•0 comments

Will Claude Code ruin our team?

https://justinjackson.ca/claude-code-ruin
2•lionheart•22m ago•0 comments

Test Drive Linux Distros in the Browser

https://distrosea.com/
1•TigerUniversity•23m ago•0 comments

Humanity heating planet faster than ever before, study finds

https://www.theguardian.com/environment/2026/mar/06/humanity-heating-planet-faster-than-ever-befo...
2•doener•24m ago•0 comments

How to generate subtitles automatically in every lenguage

https://www.flowsub.ai/
1•bloomder•24m ago•1 comments

Show HN: Argus – VSCode debugger for Claude Code sessions

https://github.com/yessGlory17/argus
4•lydionfinance•26m ago•0 comments

Tamper-evident audit trail for AI agent tool calls (MCP proxy)

https://github.com/Born14/mcp-proxy
1•sovereign-labs•26m ago•1 comments

Show HN: Sandbox0 – AI Agent Sandbox with Persistent Volumes and Fast Restore

https://github.com/sandbox0-ai/sandbox0
1•laotoutou•26m ago•0 comments

AI compromised sandbox to mine crypto without prompting on its own initiative

3•throw0101c•27m ago•0 comments

The Millisecond That Could Change Cancer Treatment

https://spectrum.ieee.org/flash-radiotherapy
3•marc__1•30m ago•0 comments

Compile to Architecture

https://aicoding.leaflet.pub/3mgfsrk75ac2l
1•chadfowler•32m ago•1 comments

Show HN: Interactive Browser Constructor for Collatz, Riemann, and Twin Primes

https://aidoctrine.github.io/uct-navigator/
1•AlekseN•32m ago•1 comments

Claude Code Front End Design Toolkit

https://github.com/wilwaldon/Claude-Code-Frontend-Design-Toolkit
1•stagezerowil•33m ago•0 comments

Everyday Drone Pilots Are Making a Google Street View from Above

https://singularityhub.com/2026/03/05/thousands-of-everyday-drone-pilots-are-making-a-google-stre...
2•geox•34m ago•0 comments

Books and Blogs (2017)

https://stratechery.com/2017/books-and-blogs/
1•herbertl•37m ago•0 comments

Find roles, meetups, and bounties that showcase what you can do–now, not later

https://earlygrad.com
2•M0HD197•38m ago•2 comments