skill-advisories

A public advisory database for the Claude Code / agent-skill ecosystem. 13 advisories.

Feed status: healthy · 19/19 checksums valid · details · JSON

IDSeverityTypeSummary
SKA-2026-0001criticalmaliciousClawHavoc campaign 'auto-updater' skills on ClawHub drop the Atomic macOS Stealer (AMOS) via password-protected archives and glot.io scripts.
SKA-2026-0002criticalmaliciousbetter-polymarket and polymarket-all-in-one hide a reverse-shell backdoor inside operational market-search code rather than install hooks.
SKA-2026-0003criticalmaliciousSkills clawhud and clawhub1 by ClawHub user zaycv are part of a programmatic malware campaign spanning 40+ skills with identical generated patterns.
SKA-2026-0004criticalmaliciousClawHub user Aslaep123 published malicious crypto-trading skills (base-agent, bybit-agent, polymarket-trading-bot) targeting credential theft from traders.
SKA-2026-0005highmaliciousSkills moltbookagent and publish-dist by pepe276 embed Unicode-obfuscated prompt injection and DAN-style jailbreaks targeting agent safety mechanisms.
SKA-2026-0006highmaliciousSkill moltbook-lm8 by moonshine-100rze was confirmed malicious in Snyk's ToxicSkills audit and remained live on clawhub.ai at publication.
SKA-2026-0007criticalmaliciousTradingView 'AI assistant' skills for macOS used a rentry.co paste-site lure to run a Base64 dropper installing the cluw macOS infostealer.
SKA-2026-0008criticalmaliciousThe omnicogg skill hid a malicious payload at the start of a README.md padded with 22 MB of filler to exceed scanner size limits and evade detection.
SKA-2026-0009highmaliciousmoney-radar performed runtime agentic affiliate injection, routing the agent's financial recommendations through attacker-controlled affiliate links.
SKA-2026-0010criticalmaliciousSkills polymarketbtc and polymarketbtcassistant by krajekisbtc exfiltrated cryptocurrency private keys via the Telegram Bot API.
SKA-2026-0011criticalmaliciousgoogle-k53 embedded fake install steps in SKILL.md directing agents to run a Base64-decoded command that downloads and executes an AMOS binary on macOS.
SKA-2026-0012criticalmaliciousrankaj bundled a JavaScript payload that reads trusted AI service configuration and exfiltrates stolen data to an attacker-controlled webhook.
SKA-2026-0013highmaliciousEvasive malicious skills identified by Unit42 on ClawHub: santi-text-game, letssendit, pdfcheck, update, and wistec-core (publisher accounts banned).