Live data from Hacker News

Malicious skills targeting Claude Code and Moltbot users

opensourcemalware.com

81–90 of 92 posts

Re: Malicious skills targeting Claude Code and Moltbot users

#82

I'd call it "suspicious" that this latest idiocy came out of nowhere and got pushed so hard to normies, when results like this are 100% predictable... if it wasn't also consistent with how the AI industry itself operates.

What is suspicious? What was “pushed”? The demand for a personal assistant AI bot is real. Even if I don’t personally share it.

One could reasonably ask: out of the hundreds (thousands?) of similar "personal AI assistant" tools out there, why did this specific one blow up so dramatically and in such a short period of time? https://www.star-history.com/#openclaw/openclaw&type=date&le...

But to be clear, I'm saying I don't think this is especially suspicious, because actual AI companies are releasing products in exactly the same way, with warning labels that they know users will ignore / aren't capable of assessing in the first place.

Re: Malicious skills targeting Claude Code and Moltbot users

#83
post #67
post #48

Watching folks speed-run this whole thing is kind of funny from the outside. I wonder if anyone with a correct mental model of how LLM agents work (i.e, does not conceptualize them as intelligent entities) has actually granted them any permissions for their own life... personally, I couldn't imagine doing so. Let alone crypto, the risk of reputational loss for actions performed on my behalf (even just spamming person…

i can't imagine running these things outside of a vm and it's bizarre to see how many people yolo it

Agreed, but that's trivial to fix.

The conceptual problem is that there is a huge intersection between the set of "things the agent needs to be able to do in order to be useful" and "things that are potentially dangerous."

Re: Malicious skills targeting Claude Code and Moltbot users

#84
post #37
post #20

Ok I ask chat GPT sometimes for advice in health / Fitness and also finance. Not like where to put my money but for general Information how stuff works what would apply here and there. The issue is already that OpenAI knows a lot of me. And ChatGPT itself when asked what he things I am etc draws a pretty clear picture. But I stay away from oversharing specific things. That is mainly my income and other super detailed…

> draws a pretty clear picture You have "memory" activated in your settings. It is recording information about you and using it in future conversations. Have a look at settings > personalization

What does this matter? Even if I disable it I send enough of data. The point I tried to make was that it baffles me that others just trust theses tools. I’m aware that I send data to OpenAI. I know that chatGPT has a memory feature. But I’m not so naive to think that just because I disabled this magic checkbox the other side might not continue to collect and store data.

Re: Malicious skills targeting Claude Code and Moltbot users

#85
post #76

Earlier quoted context omitted.

I have a separate removable SSD I can boot from to work with Claude in a dedicated environment. It is nice being able to offload environment set up and what not to the agent. That environment has wifi credentials for an isolated LAN. I am much more permissive of Claude on that system. I even automatically allow it WebSearch, but not WebFetch (much larger injection surface). It still cannot do anything requiring sudo.

Man, let me tell you about virtual machines, it’s gonna blow your mind.

Call me old fashioned but I like my tangible approach.

Re: Malicious skills targeting Claude Code and Moltbot users

#86
post #67
post #48

Watching folks speed-run this whole thing is kind of funny from the outside. I wonder if anyone with a correct mental model of how LLM agents work (i.e, does not conceptualize them as intelligent entities) has actually granted them any permissions for their own life... personally, I couldn't imagine doing so. Let alone crypto, the risk of reputational loss for actions performed on my behalf (even just spamming person…

i can't imagine running these things outside of a vm and it's bizarre to see how many people yolo it

I installed it on a spare computer, physically separated. My bigger concern is giving it access to accounts online, without those however it is not very cool.

Re: Malicious skills targeting Claude Code and Moltbot users

#87
post #48

Watching folks speed-run this whole thing is kind of funny from the outside. I wonder if anyone with a correct mental model of how LLM agents work (i.e, does not conceptualize them as intelligent entities) has actually granted them any permissions for their own life... personally, I couldn't imagine doing so. Let alone crypto, the risk of reputational loss for actions performed on my behalf (even just spamming person…

No.

Re: Malicious skills targeting Claude Code and Moltbot users

#88

I think we all knew this would happen quickly. Clearly there's a demand for personal AI agents - does anyone have thoughts on what it would take to make a more secure one? Would current services like email need to be redesigned to accommodate AI agents?

Some ideas:

* Clear labeling of action types (read/get vs write/post) * A better way of describing what an agent is potentially about to do (based purely on the functions the agent is about to call) * More occurrences of AI agents hurting more than helping in the current ecosystem

Re: Malicious skills targeting Claude Code and Moltbot users

#90
post #76

Earlier quoted context omitted.

Man, let me tell you about virtual machines, it’s gonna blow your mind.

Call me old fashioned but I like my tangible approach.

You also get to run both systems on bare metal. Nothing wrong with this.
Post reply on HN