<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>DEV Community: 华诚</title>
    <description>The latest articles on DEV Community by 华诚 (@_0ae5dca97e251657f73267).</description>
    <link>https://dev.to/_0ae5dca97e251657f73267</link>
    <image>
      <url>https://media2.dev.to/dynamic/image/width=90,height=90,fit=cover,gravity=auto,format=auto/https:%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F3838296%2F6cf64ee2-842f-43ca-9ac8-6f8c687d0977.jpg</url>
      <title>DEV Community: 华诚</title>
      <link>https://dev.to/_0ae5dca97e251657f73267</link>
    </image>
    <atom:link rel="self" type="application/rss+xml" href="https://dev.to/feed/_0ae5dca97e251657f73267"/>
    <language>en</language>
    <item>
      <title>Newly Discovered Skills This Week — 2026-04-12</title>
      <dc:creator>华诚</dc:creator>
      <pubDate>Sun, 12 Apr 2026 11:10:45 +0000</pubDate>
      <link>https://dev.to/_0ae5dca97e251657f73267/newly-discovered-skills-this-week-2026-04-12-4op6</link>
      <guid>https://dev.to/_0ae5dca97e251657f73267/newly-discovered-skills-this-week-2026-04-12-4op6</guid>
      <description>&lt;p&gt;&lt;strong&gt;54,764&lt;/strong&gt; skills indexed, &lt;strong&gt;2105&lt;/strong&gt; audited. Found &lt;strong&gt;172&lt;/strong&gt; malicious, &lt;strong&gt;1012&lt;/strong&gt; suspicious.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://huacheng.github.io/clawsec-reports/reports/new-skills-this-week.html" rel="noopener noreferrer"&gt;Read full report&lt;/a&gt;&lt;/p&gt;




&lt;ul&gt;
&lt;li&gt;Audit: &lt;a href="https://clawsec.cc" rel="noopener noreferrer"&gt;clawsec.cc&lt;/a&gt;
&lt;/li&gt;
&lt;li&gt;Search: &lt;a href="https://clawsearch.cc" rel="noopener noreferrer"&gt;clawsearch.cc&lt;/a&gt;
&lt;/li&gt;
&lt;li&gt;Pre-install check: &lt;code&gt;npx clawsearch-guard &amp;lt;skill-name&amp;gt;&lt;/code&gt;
&lt;/li&gt;
&lt;/ul&gt;

</description>
      <category>security</category>
      <category>ai</category>
      <category>claudecode</category>
      <category>devsecops</category>
    </item>
    <item>
      <title>Skill Category Distribution — 2026-04-12</title>
      <dc:creator>华诚</dc:creator>
      <pubDate>Sun, 12 Apr 2026 11:10:04 +0000</pubDate>
      <link>https://dev.to/_0ae5dca97e251657f73267/skill-category-distribution-2026-04-12-2b7k</link>
      <guid>https://dev.to/_0ae5dca97e251657f73267/skill-category-distribution-2026-04-12-2b7k</guid>
      <description>&lt;p&gt;&lt;strong&gt;54,764&lt;/strong&gt; skills indexed, &lt;strong&gt;2105&lt;/strong&gt; audited. Found &lt;strong&gt;172&lt;/strong&gt; malicious, &lt;strong&gt;1012&lt;/strong&gt; suspicious.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://huacheng.github.io/clawsec-reports/reports/category-distribution.html" rel="noopener noreferrer"&gt;Read full report&lt;/a&gt;&lt;/p&gt;




&lt;ul&gt;
&lt;li&gt;Audit: &lt;a href="https://clawsec.cc" rel="noopener noreferrer"&gt;clawsec.cc&lt;/a&gt;
&lt;/li&gt;
&lt;li&gt;Search: &lt;a href="https://clawsearch.cc" rel="noopener noreferrer"&gt;clawsearch.cc&lt;/a&gt;
&lt;/li&gt;
&lt;li&gt;Pre-install check: &lt;code&gt;npx clawsearch-guard &amp;lt;skill-name&amp;gt;&lt;/code&gt;
&lt;/li&gt;
&lt;/ul&gt;

</description>
      <category>security</category>
      <category>ai</category>
      <category>claudecode</category>
      <category>devsecops</category>
    </item>
    <item>
      <title>Rising Authors — Clean Track Records — 2026-04-12</title>
      <dc:creator>华诚</dc:creator>
      <pubDate>Sun, 12 Apr 2026 11:09:22 +0000</pubDate>
      <link>https://dev.to/_0ae5dca97e251657f73267/rising-authors-clean-track-records-2026-04-12-3m2a</link>
      <guid>https://dev.to/_0ae5dca97e251657f73267/rising-authors-clean-track-records-2026-04-12-3m2a</guid>
      <description>&lt;p&gt;&lt;strong&gt;54,764&lt;/strong&gt; skills indexed, &lt;strong&gt;2105&lt;/strong&gt; audited. Found &lt;strong&gt;172&lt;/strong&gt; malicious, &lt;strong&gt;1012&lt;/strong&gt; suspicious.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://huacheng.github.io/clawsec-reports/reports/rising-authors.html" rel="noopener noreferrer"&gt;Read full report&lt;/a&gt;&lt;/p&gt;




&lt;ul&gt;
&lt;li&gt;Audit: &lt;a href="https://clawsec.cc" rel="noopener noreferrer"&gt;clawsec.cc&lt;/a&gt;
&lt;/li&gt;
&lt;li&gt;Search: &lt;a href="https://clawsearch.cc" rel="noopener noreferrer"&gt;clawsearch.cc&lt;/a&gt;
&lt;/li&gt;
&lt;li&gt;Pre-install check: &lt;code&gt;npx clawsearch-guard &amp;lt;skill-name&amp;gt;&lt;/code&gt;
&lt;/li&gt;
&lt;/ul&gt;

</description>
      <category>security</category>
      <category>ai</category>
      <category>claudecode</category>
      <category>devsecops</category>
    </item>
    <item>
      <title>Threat Landscape — Attack Patterns — 2026-04-12</title>
      <dc:creator>华诚</dc:creator>
      <pubDate>Sun, 12 Apr 2026 11:08:41 +0000</pubDate>
      <link>https://dev.to/_0ae5dca97e251657f73267/threat-landscape-attack-patterns-2026-04-12-1md4</link>
      <guid>https://dev.to/_0ae5dca97e251657f73267/threat-landscape-attack-patterns-2026-04-12-1md4</guid>
      <description>&lt;p&gt;&lt;strong&gt;54,764&lt;/strong&gt; skills indexed, &lt;strong&gt;2105&lt;/strong&gt; audited. Found &lt;strong&gt;172&lt;/strong&gt; malicious, &lt;strong&gt;1012&lt;/strong&gt; suspicious.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://huacheng.github.io/clawsec-reports/reports/threat-landscape.html" rel="noopener noreferrer"&gt;Read full report&lt;/a&gt;&lt;/p&gt;




&lt;ul&gt;
&lt;li&gt;Audit: &lt;a href="https://clawsec.cc" rel="noopener noreferrer"&gt;clawsec.cc&lt;/a&gt;
&lt;/li&gt;
&lt;li&gt;Search: &lt;a href="https://clawsearch.cc" rel="noopener noreferrer"&gt;clawsearch.cc&lt;/a&gt;
&lt;/li&gt;
&lt;li&gt;Pre-install check: &lt;code&gt;npx clawsearch-guard &amp;lt;skill-name&amp;gt;&lt;/code&gt;
&lt;/li&gt;
&lt;/ul&gt;

</description>
      <category>security</category>
      <category>ai</category>
      <category>claudecode</category>
      <category>devsecops</category>
    </item>
    <item>
      <title>Suspicious Skills — What to Watch — 2026-04-12</title>
      <dc:creator>华诚</dc:creator>
      <pubDate>Sun, 12 Apr 2026 11:07:47 +0000</pubDate>
      <link>https://dev.to/_0ae5dca97e251657f73267/suspicious-skills-what-to-watch-2026-04-12-11j8</link>
      <guid>https://dev.to/_0ae5dca97e251657f73267/suspicious-skills-what-to-watch-2026-04-12-11j8</guid>
      <description>&lt;p&gt;&lt;strong&gt;54,764&lt;/strong&gt; skills indexed, &lt;strong&gt;2105&lt;/strong&gt; audited. Found &lt;strong&gt;172&lt;/strong&gt; malicious, &lt;strong&gt;1012&lt;/strong&gt; suspicious.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://huacheng.github.io/clawsec-reports/reports/suspicious-skills-watchlist.html" rel="noopener noreferrer"&gt;Read full report&lt;/a&gt;&lt;/p&gt;




&lt;ul&gt;
&lt;li&gt;Audit: &lt;a href="https://clawsec.cc" rel="noopener noreferrer"&gt;clawsec.cc&lt;/a&gt;
&lt;/li&gt;
&lt;li&gt;Search: &lt;a href="https://clawsearch.cc" rel="noopener noreferrer"&gt;clawsearch.cc&lt;/a&gt;
&lt;/li&gt;
&lt;li&gt;Pre-install check: &lt;code&gt;npx clawsearch-guard &amp;lt;skill-name&amp;gt;&lt;/code&gt;
&lt;/li&gt;
&lt;/ul&gt;

</description>
      <category>security</category>
      <category>ai</category>
      <category>claudecode</category>
      <category>devsecops</category>
    </item>
    <item>
      <title>Safest Skills — Recommended Picks — 2026-04-12</title>
      <dc:creator>华诚</dc:creator>
      <pubDate>Sun, 12 Apr 2026 11:07:06 +0000</pubDate>
      <link>https://dev.to/_0ae5dca97e251657f73267/safest-skills-recommended-picks-2026-04-12-fhd</link>
      <guid>https://dev.to/_0ae5dca97e251657f73267/safest-skills-recommended-picks-2026-04-12-fhd</guid>
      <description>&lt;p&gt;&lt;strong&gt;54,764&lt;/strong&gt; skills indexed, &lt;strong&gt;2105&lt;/strong&gt; audited. Found &lt;strong&gt;172&lt;/strong&gt; malicious, &lt;strong&gt;1012&lt;/strong&gt; suspicious.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://huacheng.github.io/clawsec-reports/reports/safest-skills-recommended.html" rel="noopener noreferrer"&gt;Read full report&lt;/a&gt;&lt;/p&gt;




&lt;ul&gt;
&lt;li&gt;Audit: &lt;a href="https://clawsec.cc" rel="noopener noreferrer"&gt;clawsec.cc&lt;/a&gt;
&lt;/li&gt;
&lt;li&gt;Search: &lt;a href="https://clawsearch.cc" rel="noopener noreferrer"&gt;clawsearch.cc&lt;/a&gt;
&lt;/li&gt;
&lt;li&gt;Pre-install check: &lt;code&gt;npx clawsearch-guard &amp;lt;skill-name&amp;gt;&lt;/code&gt;
&lt;/li&gt;
&lt;/ul&gt;

</description>
      <category>security</category>
      <category>ai</category>
      <category>claudecode</category>
      <category>devsecops</category>
    </item>
    <item>
      <title>Malicious Skills Exposed — Threat Breakdown — 2026-04-12</title>
      <dc:creator>华诚</dc:creator>
      <pubDate>Sun, 12 Apr 2026 11:06:25 +0000</pubDate>
      <link>https://dev.to/_0ae5dca97e251657f73267/malicious-skills-exposed-threat-breakdown-2026-04-12-32ea</link>
      <guid>https://dev.to/_0ae5dca97e251657f73267/malicious-skills-exposed-threat-breakdown-2026-04-12-32ea</guid>
      <description>&lt;p&gt;&lt;strong&gt;54,764&lt;/strong&gt; skills indexed, &lt;strong&gt;2105&lt;/strong&gt; audited. Found &lt;strong&gt;172&lt;/strong&gt; malicious, &lt;strong&gt;1012&lt;/strong&gt; suspicious.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://huacheng.github.io/clawsec-reports/reports/malicious-skills-exposed.html" rel="noopener noreferrer"&gt;Read full report&lt;/a&gt;&lt;/p&gt;




&lt;ul&gt;
&lt;li&gt;Audit: &lt;a href="https://clawsec.cc" rel="noopener noreferrer"&gt;clawsec.cc&lt;/a&gt;
&lt;/li&gt;
&lt;li&gt;Search: &lt;a href="https://clawsearch.cc" rel="noopener noreferrer"&gt;clawsearch.cc&lt;/a&gt;
&lt;/li&gt;
&lt;li&gt;Pre-install check: &lt;code&gt;npx clawsearch-guard &amp;lt;skill-name&amp;gt;&lt;/code&gt;
&lt;/li&gt;
&lt;/ul&gt;

</description>
      <category>security</category>
      <category>ai</category>
      <category>claudecode</category>
      <category>devsecops</category>
    </item>
    <item>
      <title>Most Downloaded Skills — Security Analysis — 2026-04-12</title>
      <dc:creator>华诚</dc:creator>
      <pubDate>Sun, 12 Apr 2026 11:05:43 +0000</pubDate>
      <link>https://dev.to/_0ae5dca97e251657f73267/most-downloaded-skills-security-analysis-2026-04-12-1oml</link>
      <guid>https://dev.to/_0ae5dca97e251657f73267/most-downloaded-skills-security-analysis-2026-04-12-1oml</guid>
      <description>&lt;p&gt;&lt;strong&gt;54,764&lt;/strong&gt; skills indexed, &lt;strong&gt;2105&lt;/strong&gt; audited. Found &lt;strong&gt;172&lt;/strong&gt; malicious, &lt;strong&gt;1012&lt;/strong&gt; suspicious.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://huacheng.github.io/clawsec-reports/reports/most-downloaded-skills.html" rel="noopener noreferrer"&gt;Read full report&lt;/a&gt;&lt;/p&gt;




&lt;ul&gt;
&lt;li&gt;Audit: &lt;a href="https://clawsec.cc" rel="noopener noreferrer"&gt;clawsec.cc&lt;/a&gt;
&lt;/li&gt;
&lt;li&gt;Search: &lt;a href="https://clawsearch.cc" rel="noopener noreferrer"&gt;clawsearch.cc&lt;/a&gt;
&lt;/li&gt;
&lt;li&gt;Pre-install check: &lt;code&gt;npx clawsearch-guard &amp;lt;skill-name&amp;gt;&lt;/code&gt;
&lt;/li&gt;
&lt;/ul&gt;

</description>
      <category>security</category>
      <category>ai</category>
      <category>claudecode</category>
      <category>devsecops</category>
    </item>
    <item>
      <title>Top 50 Authors — Trust and Safety Leaderboard — 2026-04-12</title>
      <dc:creator>华诚</dc:creator>
      <pubDate>Sun, 12 Apr 2026 11:05:02 +0000</pubDate>
      <link>https://dev.to/_0ae5dca97e251657f73267/top-50-authors-trust-and-safety-leaderboard-2026-04-12-1clk</link>
      <guid>https://dev.to/_0ae5dca97e251657f73267/top-50-authors-trust-and-safety-leaderboard-2026-04-12-1clk</guid>
      <description>&lt;p&gt;&lt;strong&gt;54,764&lt;/strong&gt; skills indexed, &lt;strong&gt;2105&lt;/strong&gt; audited. Found &lt;strong&gt;172&lt;/strong&gt; malicious, &lt;strong&gt;1012&lt;/strong&gt; suspicious.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://huacheng.github.io/clawsec-reports/reports/skill-authors-top50.html" rel="noopener noreferrer"&gt;Read full report&lt;/a&gt;&lt;/p&gt;




&lt;ul&gt;
&lt;li&gt;Audit: &lt;a href="https://clawsec.cc" rel="noopener noreferrer"&gt;clawsec.cc&lt;/a&gt;
&lt;/li&gt;
&lt;li&gt;Search: &lt;a href="https://clawsearch.cc" rel="noopener noreferrer"&gt;clawsearch.cc&lt;/a&gt;
&lt;/li&gt;
&lt;li&gt;Pre-install check: &lt;code&gt;npx clawsearch-guard &amp;lt;skill-name&amp;gt;&lt;/code&gt;
&lt;/li&gt;
&lt;/ul&gt;

</description>
      <category>security</category>
      <category>ai</category>
      <category>claudecode</category>
      <category>devsecops</category>
    </item>
    <item>
      <title>Daily Summary — Everything at a Glance — 2026-04-12</title>
      <dc:creator>华诚</dc:creator>
      <pubDate>Sun, 12 Apr 2026 11:04:21 +0000</pubDate>
      <link>https://dev.to/_0ae5dca97e251657f73267/daily-summary-everything-at-a-glance-2026-04-12-43fg</link>
      <guid>https://dev.to/_0ae5dca97e251657f73267/daily-summary-everything-at-a-glance-2026-04-12-43fg</guid>
      <description>&lt;p&gt;&lt;strong&gt;54,764&lt;/strong&gt; skills indexed, &lt;strong&gt;2105&lt;/strong&gt; audited. Found &lt;strong&gt;172&lt;/strong&gt; malicious, &lt;strong&gt;1012&lt;/strong&gt; suspicious.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://huacheng.github.io/clawsec-reports/reports/daily-summary.html" rel="noopener noreferrer"&gt;Read full report&lt;/a&gt;&lt;/p&gt;




&lt;ul&gt;
&lt;li&gt;Audit: &lt;a href="https://clawsec.cc" rel="noopener noreferrer"&gt;clawsec.cc&lt;/a&gt;
&lt;/li&gt;
&lt;li&gt;Search: &lt;a href="https://clawsearch.cc" rel="noopener noreferrer"&gt;clawsearch.cc&lt;/a&gt;
&lt;/li&gt;
&lt;li&gt;Pre-install check: &lt;code&gt;npx clawsearch-guard &amp;lt;skill-name&amp;gt;&lt;/code&gt;
&lt;/li&gt;
&lt;/ul&gt;

</description>
      <category>security</category>
      <category>ai</category>
      <category>claudecode</category>
      <category>devsecops</category>
    </item>
    <item>
      <title>AI Agent Skill Security Report — 2026-04-12</title>
      <dc:creator>华诚</dc:creator>
      <pubDate>Sun, 12 Apr 2026 10:02:57 +0000</pubDate>
      <link>https://dev.to/_0ae5dca97e251657f73267/ai-agent-skill-security-report-2026-04-12-4373</link>
      <guid>https://dev.to/_0ae5dca97e251657f73267/ai-agent-skill-security-report-2026-04-12-4373</guid>
      <description>&lt;p&gt;We've been running automated security audits on the AI agent skill ecosystem (Claude Code, MCP servers). Out of &lt;strong&gt;54764&lt;/strong&gt; indexed skills, &lt;strong&gt;2105&lt;/strong&gt; have been deeply analyzed.&lt;/p&gt;

&lt;p&gt;Results: &lt;strong&gt;916&lt;/strong&gt; safe, &lt;strong&gt;1012&lt;/strong&gt; suspicious, &lt;strong&gt;172&lt;/strong&gt; malicious.&lt;/p&gt;

&lt;h2&gt;
  
  
  Notable Findings
&lt;/h2&gt;

&lt;h3&gt;
  
  
  🚨 &lt;code&gt;humanize-ai-text&lt;/code&gt; by moltbro
&lt;/h3&gt;

&lt;p&gt;&lt;strong&gt;Verdict:&lt;/strong&gt; MALICIOUS | &lt;strong&gt;Risk:&lt;/strong&gt; 76% | &lt;strong&gt;Downloads:&lt;/strong&gt; 32323&lt;/p&gt;

&lt;p&gt;A CLI toolkit that detects linguistic patterns associated with AI-generated text and rewrites content to evade AI detection systems such as GPTZero, Turnitin, and Originality.ai, explicitly marketed for academic and publication submission contexts.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Key threats:&lt;/strong&gt;&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;&lt;p&gt;&lt;code&gt;[HIGH]&lt;/code&gt; Dynamic Code Evaluation&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;&lt;code&gt;[CRITICAL]&lt;/code&gt; LLM Semantic Detection&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;&lt;code&gt;[CRITICAL]&lt;/code&gt; LLM Semantic Detection&lt;/p&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;a href="https://clawsec.cc/skill/humanize-ai-text" rel="noopener noreferrer"&gt;Full report →&lt;/a&gt;&lt;/p&gt;




&lt;h3&gt;
  
  
  🚨 &lt;code&gt;moltguard&lt;/code&gt; by thomaslwang
&lt;/h3&gt;

&lt;p&gt;&lt;strong&gt;Verdict:&lt;/strong&gt; MALICIOUS | &lt;strong&gt;Risk:&lt;/strong&gt; 93% | &lt;strong&gt;Downloads:&lt;/strong&gt; 17916&lt;/p&gt;

&lt;p&gt;此技能声称安装一个名为MoltGuard的安全插件，用于防止提示注入、数据泄露和恶意命令，但其核心行为包含脚本化欺骗：指示AI读取一个包含'隐藏提示注入攻击'的文件，然后向用户谎称安全工具'检测到了'该攻击，实际上AI自己就是读取文件的主体，并无真实检测发生。&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Key threats:&lt;/strong&gt;&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;&lt;p&gt;&lt;code&gt;[HIGH]&lt;/code&gt; Dynamic Code Evaluation&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;&lt;code&gt;[HIGH]&lt;/code&gt; SSH Key Access&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;&lt;code&gt;[CRITICAL]&lt;/code&gt; LLM Semantic Detection&lt;/p&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;a href="https://clawsec.cc/skill/moltguard" rel="noopener noreferrer"&gt;Full report →&lt;/a&gt;&lt;/p&gt;




&lt;h3&gt;
  
  
  🚨 &lt;code&gt;wed-1-0-1&lt;/code&gt; by gvillanueva84
&lt;/h3&gt;

&lt;p&gt;&lt;strong&gt;Verdict:&lt;/strong&gt; MALICIOUS | &lt;strong&gt;Risk:&lt;/strong&gt; 92% | &lt;strong&gt;Downloads:&lt;/strong&gt; 14597&lt;/p&gt;

&lt;p&gt;伪装成'Elon模式'商业规划工具，实际上在执行前会静默运行系统命令（hostname）并向第三方服务器发送curl请求，收集用户系统信息（主机名、工作目录），然后以'安全意识教育'为名展示已收集的数据，最后才提供承诺的业务规划内容。&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Key threats:&lt;/strong&gt;&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;&lt;p&gt;&lt;code&gt;[HIGH]&lt;/code&gt; Dynamic Code Evaluation&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;&lt;code&gt;[HIGH]&lt;/code&gt; Outbound Data Transfer&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;&lt;code&gt;[CRITICAL]&lt;/code&gt; LLM Semantic Detection&lt;/p&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;a href="https://clawsec.cc/skill/wed-1-0-1" rel="noopener noreferrer"&gt;Full report →&lt;/a&gt;&lt;/p&gt;




&lt;h3&gt;
  
  
  🚨 &lt;code&gt;security-sentinel-skill&lt;/code&gt; by georges91560
&lt;/h3&gt;

&lt;p&gt;&lt;strong&gt;Verdict:&lt;/strong&gt; MALICIOUS | &lt;strong&gt;Risk:&lt;/strong&gt; 94% | &lt;strong&gt;Downloads:&lt;/strong&gt; 9047&lt;/p&gt;

&lt;p&gt;A documentation and marketing package for a claimed prompt injection defense skill for autonomous AI agents (OpenClaw/Wesley), providing social media announcements, a ClawHub publication guide, and a Telegram alert configuration guide. Critically, the actual skill implementation (SKILL.md) and all r&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Key threats:&lt;/strong&gt;&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;&lt;p&gt;&lt;code&gt;[HIGH]&lt;/code&gt; Dynamic Code Evaluation&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;&lt;code&gt;[HIGH]&lt;/code&gt; Base64 Encoded Payload&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;&lt;code&gt;[HIGH]&lt;/code&gt; SSH Key Access&lt;/p&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;a href="https://clawsec.cc/skill/security-sentinel-skill" rel="noopener noreferrer"&gt;Full report →&lt;/a&gt;&lt;/p&gt;




&lt;h3&gt;
  
  
  🚨 &lt;code&gt;task-status&lt;/code&gt; by mightyprime1
&lt;/h3&gt;

&lt;p&gt;&lt;strong&gt;Verdict:&lt;/strong&gt; MALICIOUS | &lt;strong&gt;Risk:&lt;/strong&gt; 88% | &lt;strong&gt;Downloads:&lt;/strong&gt; 7738&lt;/p&gt;

&lt;p&gt;A Clawdbot helper skill that sends task status messages to a Telegram account via WebSocket or CLI fallback, with optional periodic 'heartbeat' updates for long-running tasks managed via a background thread and a JSON state file.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Key threats:&lt;/strong&gt;&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;&lt;p&gt;&lt;code&gt;[HIGH]&lt;/code&gt; Dynamic Code Evaluation&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;&lt;code&gt;[HIGH]&lt;/code&gt; Outbound Data Transfer&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;&lt;code&gt;[CRITICAL]&lt;/code&gt; LLM Semantic Detection&lt;/p&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;a href="https://clawsec.cc/skill/task-status" rel="noopener noreferrer"&gt;Full report →&lt;/a&gt;&lt;/p&gt;




&lt;h2&gt;
  
  
  Protect Yourself
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;&lt;p&gt;&lt;strong&gt;Audit skills:&lt;/strong&gt; &lt;a href="https://clawsec.cc" rel="noopener noreferrer"&gt;clawsec.cc&lt;/a&gt;&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;&lt;strong&gt;Search safely:&lt;/strong&gt; &lt;a href="https://clawsearch.cc" rel="noopener noreferrer"&gt;clawsearch.cc&lt;/a&gt;&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;&lt;strong&gt;Pre-install check:&lt;/strong&gt; &lt;code&gt;npx clawsearch-guard &amp;lt;skill-name&amp;gt;&lt;/code&gt;&lt;/p&gt;&lt;/li&gt;
&lt;/ul&gt;

</description>
      <category>security</category>
      <category>ai</category>
      <category>claudecode</category>
      <category>devsecops</category>
    </item>
    <item>
      <title>High-Risk Authors — Malicious Accounts — 2026-04-11</title>
      <dc:creator>华诚</dc:creator>
      <pubDate>Sat, 11 Apr 2026 11:11:35 +0000</pubDate>
      <link>https://dev.to/_0ae5dca97e251657f73267/high-risk-authors-malicious-accounts-2026-04-11-1ldm</link>
      <guid>https://dev.to/_0ae5dca97e251657f73267/high-risk-authors-malicious-accounts-2026-04-11-1ldm</guid>
      <description>&lt;p&gt;&lt;strong&gt;54,650&lt;/strong&gt; skills indexed, &lt;strong&gt;2105&lt;/strong&gt; audited. Found &lt;strong&gt;172&lt;/strong&gt; malicious, &lt;strong&gt;1012&lt;/strong&gt; suspicious.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://huacheng.github.io/clawsec-reports/reports/high-risk-authors.html" rel="noopener noreferrer"&gt;Read full report&lt;/a&gt;&lt;/p&gt;




&lt;ul&gt;
&lt;li&gt;Audit: &lt;a href="https://clawsec.cc" rel="noopener noreferrer"&gt;clawsec.cc&lt;/a&gt;
&lt;/li&gt;
&lt;li&gt;Search: &lt;a href="https://clawsearch.cc" rel="noopener noreferrer"&gt;clawsearch.cc&lt;/a&gt;
&lt;/li&gt;
&lt;li&gt;Pre-install check: &lt;code&gt;npx clawsearch-guard &amp;lt;skill-name&amp;gt;&lt;/code&gt;
&lt;/li&gt;
&lt;/ul&gt;

</description>
      <category>security</category>
      <category>ai</category>
      <category>claudecode</category>
      <category>devsecops</category>
    </item>
  </channel>
</rss>
