Snyk researchers discovered a sophisticated supply chain attack targeting OpenClaw AI agent users through ClawHub. The attack uses a fake Google skill that tricks users into manually installing malware by embedding malicious instructions in SKILL.md files. Rather than hiding code in dependencies, attackers exploit the

6m read time From snyk.io
Post cover image
Table of contents
The SKILL.md "Prerequisite" trap injects malwareThe "ToxicSkills" predictionHow Evo secures the agentic futureUnifying Control for Agentic AI With Evo By Snyk

Sort: