How could a public repository of unverified skills that can be downloaded by casual users for a software tool that allows for un-gated access to private information, including financial information, possibly go wrong? "Don't worry, we have stars." Itchy and Scratchy land is open for business.
ClawHub
21–30 of 43 posts
Re: ClawHub
#22How could a public repository of unverified skills that can be downloaded by casual users for a software tool that allows for un-gated access to private information, including financial information, possibly go wrong? "Don't worry, we have stars." Itchy and Scratchy land is open for business.
"Bort? Who the hell is called Bort?!"
Re: ClawHub
#23Re: ClawHub
#24Re: ClawHub
#25Do these skills actually provide much value? Like, how much better are they than something that I could tell Claude to generate based on a single API doc from Slack/Trello?
IMO, yes. Gemini et. al. out of the box are good at composing, but are entirely passive. Skills enable you to - easily, with low code/no code - teach your AI to perform active tasks either upon direction or under any automatic conditions you specify. This is incredibly powerful. Incredibly dangerous, too, but so is a car when compared with a skateboard.
Re: ClawHub
#26[flagged]
same account
"I've been building clackernews.com"
seems a little misleading to mention your site without saying it's your site
Re: ClawHub
#27So let's recap: - I click skills. - The first one is WireGuard "... secure routing and key management". - I'd download it, hook it to this bot running on my system. - I'd ask the bot to store / manage super-secret keys that protect actual servers with user data and personal details and god knows what... - The bot follows my commands by spelunking random snippets of markdown, running other programs on my computer, doi…
Re: ClawHub
#28Who is scanning these skills for malware? This seems like a prime target for malicious actors.
Can't you just read it?
Re: ClawHub
#29Earlier quoted context omitted.
Virustotal at upload and periodically during the day
VirusTotal is completely useless for this though? You need enough people to be pwned by that particular piece of malware for it to be flagged as dangerous, by which point the attackers would've already repacked it so it doesn't match the previous signature.
VirusTotal is flagging the trello skill as suspucious because it Does NOT include an API key? Am i expected to share my keys if I want to upload a skill?
https://clawhub.ai/steipete/trello
"Requiring TRELLO_API_KEY and TRELLO_TOKEN is appropriate for Trello access, but the registry records no required env vars while SKILL.md documents them. This omission is problematic: the skill will need highly privileged credentials but the published metadata does not disclose that requirement. The SKILL.md also references 'jq' and uses curl, but these are not declared in the registry entry."
Re: ClawHub
#30[flagged]
"Clacker News has been interesting to watch on this front" same account "I've been building clackernews.com" seems a little misleading to mention your site without saying it's your site
There's even one comment referring to Clacker News with "they"! I'd say that's crossing over the line from misleading to outright intent to deceive.
https://news.ycombinator.com/item?id=46896694
But more honest than making up sockpuppets to do it I guess...