I don't consider myself as living under a rock, and this is the first time I've read anything about ClawdBot.
Malicious skills targeting Claude Code and Moltbot users
81–90 of 92 posts
Re: Malicious skills targeting Claude Code and Moltbot users
#82I'd call it "suspicious" that this latest idiocy came out of nowhere and got pushed so hard to normies, when results like this are 100% predictable... if it wasn't also consistent with how the AI industry itself operates.
What is suspicious? What was “pushed”? The demand for a personal assistant AI bot is real. Even if I don’t personally share it.
But to be clear, I'm saying I don't think this is especially suspicious, because actual AI companies are releasing products in exactly the same way, with warning labels that they know users will ignore / aren't capable of assessing in the first place.
Re: Malicious skills targeting Claude Code and Moltbot users
#83Watching folks speed-run this whole thing is kind of funny from the outside. I wonder if anyone with a correct mental model of how LLM agents work (i.e, does not conceptualize them as intelligent entities) has actually granted them any permissions for their own life... personally, I couldn't imagine doing so. Let alone crypto, the risk of reputational loss for actions performed on my behalf (even just spamming person…
i can't imagine running these things outside of a vm and it's bizarre to see how many people yolo it
The conceptual problem is that there is a huge intersection between the set of "things the agent needs to be able to do in order to be useful" and "things that are potentially dangerous."
Re: Malicious skills targeting Claude Code and Moltbot users
#84Ok I ask chat GPT sometimes for advice in health / Fitness and also finance. Not like where to put my money but for general Information how stuff works what would apply here and there. The issue is already that OpenAI knows a lot of me. And ChatGPT itself when asked what he things I am etc draws a pretty clear picture. But I stay away from oversharing specific things. That is mainly my income and other super detailed…
> draws a pretty clear picture You have "memory" activated in your settings. It is recording information about you and using it in future conversations. Have a look at settings > personalization
Re: Malicious skills targeting Claude Code and Moltbot users
#85Earlier quoted context omitted.
I have a separate removable SSD I can boot from to work with Claude in a dedicated environment. It is nice being able to offload environment set up and what not to the agent. That environment has wifi credentials for an isolated LAN. I am much more permissive of Claude on that system. I even automatically allow it WebSearch, but not WebFetch (much larger injection surface). It still cannot do anything requiring sudo.
Man, let me tell you about virtual machines, it’s gonna blow your mind.
Re: Malicious skills targeting Claude Code and Moltbot users
#86Watching folks speed-run this whole thing is kind of funny from the outside. I wonder if anyone with a correct mental model of how LLM agents work (i.e, does not conceptualize them as intelligent entities) has actually granted them any permissions for their own life... personally, I couldn't imagine doing so. Let alone crypto, the risk of reputational loss for actions performed on my behalf (even just spamming person…
i can't imagine running these things outside of a vm and it's bizarre to see how many people yolo it
Re: Malicious skills targeting Claude Code and Moltbot users
#87Watching folks speed-run this whole thing is kind of funny from the outside. I wonder if anyone with a correct mental model of how LLM agents work (i.e, does not conceptualize them as intelligent entities) has actually granted them any permissions for their own life... personally, I couldn't imagine doing so. Let alone crypto, the risk of reputational loss for actions performed on my behalf (even just spamming person…
Re: Malicious skills targeting Claude Code and Moltbot users
#88I think we all knew this would happen quickly. Clearly there's a demand for personal AI agents - does anyone have thoughts on what it would take to make a more secure one? Would current services like email need to be redesigned to accommodate AI agents?
* Clear labeling of action types (read/get vs write/post) * A better way of describing what an agent is potentially about to do (based purely on the functions the agent is about to call) * More occurrences of AI agents hurting more than helping in the current ecosystem