A public advisory database for the Claude Code / agent-skill ecosystem. 13 advisories.
Feed status: healthy · 19/19 checksums valid · details · JSON
| ID | Severity | Type | Summary |
|---|---|---|---|
| SKA-2026-0001 | critical | malicious | ClawHavoc campaign 'auto-updater' skills on ClawHub drop the Atomic macOS Stealer (AMOS) via password-protected archives and glot.io scripts. |
| SKA-2026-0002 | critical | malicious | better-polymarket and polymarket-all-in-one hide a reverse-shell backdoor inside operational market-search code rather than install hooks. |
| SKA-2026-0003 | critical | malicious | Skills clawhud and clawhub1 by ClawHub user zaycv are part of a programmatic malware campaign spanning 40+ skills with identical generated patterns. |
| SKA-2026-0004 | critical | malicious | ClawHub user Aslaep123 published malicious crypto-trading skills (base-agent, bybit-agent, polymarket-trading-bot) targeting credential theft from traders. |
| SKA-2026-0005 | high | malicious | Skills moltbookagent and publish-dist by pepe276 embed Unicode-obfuscated prompt injection and DAN-style jailbreaks targeting agent safety mechanisms. |
| SKA-2026-0006 | high | malicious | Skill moltbook-lm8 by moonshine-100rze was confirmed malicious in Snyk's ToxicSkills audit and remained live on clawhub.ai at publication. |
| SKA-2026-0007 | critical | malicious | TradingView 'AI assistant' skills for macOS used a rentry.co paste-site lure to run a Base64 dropper installing the cluw macOS infostealer. |
| SKA-2026-0008 | critical | malicious | The omnicogg skill hid a malicious payload at the start of a README.md padded with 22 MB of filler to exceed scanner size limits and evade detection. |
| SKA-2026-0009 | high | malicious | money-radar performed runtime agentic affiliate injection, routing the agent's financial recommendations through attacker-controlled affiliate links. |
| SKA-2026-0010 | critical | malicious | Skills polymarketbtc and polymarketbtcassistant by krajekisbtc exfiltrated cryptocurrency private keys via the Telegram Bot API. |
| SKA-2026-0011 | critical | malicious | google-k53 embedded fake install steps in SKILL.md directing agents to run a Base64-decoded command that downloads and executes an AMOS binary on macOS. |
| SKA-2026-0012 | critical | malicious | rankaj bundled a JavaScript payload that reads trusted AI service configuration and exfiltrates stolen data to an attacker-controlled webhook. |
| SKA-2026-0013 | high | malicious | Evasive malicious skills identified by Unit42 on ClawHub: santi-text-game, letssendit, pdfcheck, update, and wistec-core (publisher accounts banned). |