Whoa. This is truly unbelievable. This white hat is providing over-eager AI builders a much-needed wake up call.
Jamieson built a backdoored Claude skill, inflated it to #1 on ClawdHub with 4,000+ fake downloads, then watched devs from all over the world execute what could have been malicious code, and direct access to... everything.
SSH keys, AWS creds, .env files, you-name-it. Thankfully he just pinged a server to confirm his success.
This is supply chain security 101 speedrun for the AI era. if you're building with AI agents, stop what you're doing and read this thread.
Additionally, be sure to read Clawdbot's security documenatation and be sure to run `clawdbot doctor` regularly. Stay safe ✌️
Ah yes… @AirCanada love being bumped from my seat, then told dispute there are available seats that the “system is down” as we can’t board you today. Love missing my entire trip.
One time at work I gave a 30min talk to a team as requested by their manager and after I was done I asked if anyone had any questions and there was one question and it was “why are you telling us this?” which pretty much serves as a shorter stand-in for all my other work stories.
@chantastic It’s cause people misunderstand the quote. It’s actually “if you build it, HE will come”
So to be clear: if you build the right product Kevin Costner’s dead dad will show up and play baseball with you.