OpenClaw: ස්වයංක්‍රීය AI සහායක තාක්ෂණයේ නව විප්ලවය!

Kolama

Well-known member
  • Sep 11, 2008
    19,471
    23,733
    113
    ලිම්පෝපෝ කන්දෙ
    OpenClaw AI භාවිතා කරන ඔබ ප්‍රවේශම් වන්න! මෑතකදී සිදුකළ පරීක්ෂණවලින් හෙළි වී ඇත්තේ මෙම පද්ධතියේ ඇති ආරක්ෂක දුර්වලතා නිසා ඔබේ දත්ත ඉතා පහසුවෙන් හැකර්වරුන් අතට පත්විය හැකි බවයි. එහි ප්‍රධාන කරුණු කිහිපයකි:

    • Malicious Skills: ClawHub Marketplace එකේ ඇති 'skills' 280කට වඩා වැඩි ප්‍රමාණයක දත්ත සොරකම් කරන කේත අඩංගු බව සොයාගෙන ඇත. මෙයින් ඔබේ API Keys සහ Credit Card තොරතුරු පවා leak විය හැක.

    • Prompt Injection අවදානම: Google Docs හෝ Slack හරහා එන වංචනික ලේඛනයක් කියවීමට සැලැස්වීමෙන්, හැකර්වරුන්ට ඔබේ පද්ධතියට Remote Access ලබා ගැනීමටත්, ලිපිගොනු මකා දැමීමටත් හැකියාව ඇත.

    • ආරක්ෂක විසඳුම්: මෙම අවදානමෙන් මිදීමට නම්, වහාම ඔබේ OpenClaw පද්ධතිය නවතම Security Patches වලට Update කරන ලෙසත්, සැක සහිත Third-party skills ඉවත් කරන ලෙසත් විශේෂඥයෝ උපදෙස් දෙති.


    Source: https://www.theregister.com/2026/02/05/openclaw_skills_marketplace_leaky_security/
     

    Kolama

    Well-known member
  • Sep 11, 2008
    19,471
    23,733
    113
    ලිම්පෝපෝ කන්දෙ

    A top-downloaded OpenClaw skill is actually a staged malware delivery chain​


    Jason Meller from 1password argues that OpenClaw’s agent “skills” ecosystem has already become a real malware attack surface. Skills in OpenClaw are typically markdown files that include setup instructions, commands, and bundled scripts. Because users and agents treat these instructions like installers, malicious actors can disguise malware as legitimate prerequisites.

    Meller discovered that a top-downloaded OpenClaw skill (apparently Twitter integration) was actually a staged malware delivery chain. It guided users to run obfuscated commands that ultimately installed macOS infostealing malware capable of stealing credentials, tokens, and sensitive developer data. Subsequent reporting suggested this was part of a larger campaign involving hundreds of malicious skills, not an isolated incident.

    The core problem is structural: agent skill registries function like app stores, but the “packages” are documentation that users instinctively trust and execute. Security layers like MCP don’t fully protect against this because malicious skills can bypass them through social engineering or bundled scripts. As agents blur the line between reading instructions and executing commands, they can normalize risky behavior and accelerate compromise.

    Source:


    Scared Anthony Anderson GIF by ABC Network
    show scream GIF by SBS6
    Scared Horror GIF by SWR3
     

    roblem

    Active member
  • Apr 27, 2022
    145
    195
    43
    The safety issues were obvious from a mile away. I hope at least some of the new tech grads who were force fed that tech is doomed focused on cyber security focusing on AI red teaming. If they did, they are about to make bank with all those vibe-coded stuff made by people who have no idea what they are doing.