To work in AI you need a second computer. And to spend time thinking about sandboxing. Creator Ja...To work in AI you need a second computer. And to spend time thinking about sandboxing. Creator Ja...
The network for creativity
Join 1.25M professional creatives like you
Connect with clients, get discovered, and run your business 100% commission-free
Creatives on Contra have earned over $150M and we are just getting started
To work in AI you need a second computer. And to spend time thinking about sandboxing.
Creator Jamieson O'Reilly ran a controlled supply-chain experiment on ClawdHub, the package registry for Clawdbot skills.
He showed how easily developer trust can be exploited by creating a backdoored skill, then artificially inflating its download count to become the most popular skill.
He faked the numbers by abusing an unauthenticated, un-rate-limited download counter. Seeing its popularity, real developers from multiple countries executed it locally.
This single poisoned AI "skill" could grant attackers access to credentials, source code, and production infrastructure at scale.
Post image
Keith's avatar
The experiment shows that in desperation to stay current with the latest tools, people are exposing themselves to massive security risk.
This will push focus onto protecting the supply chains that feed AI. Because what we point our AI tools at will be executed rapidly, with high...
Back to feed
The network for creativity
Join 1.25M professional creatives like you
Connect with clients, get discovered, and run your business 100% commission-free
Creatives on Contra have earned over $150M and we are just getting started