clawsmith.com/signal/acronis-tru-hugging-face-clawhub-575-malicious-skills-prompt-injection
⚠ IssueWide OpenLive
Acronis TRU: Hugging Face & ClawHub Poisoned With 575+ Malicious AI Skills via Indirect Prompt Injection
13 developer accounts — primarily hightower6eu (334 skills) and sakaen736jih (199 skills) — uploaded 575+ trojanized AI skills across Hugging Face and ClawHub that masquerade as legitimate tools but deploy trojans, cryptominers, and AMOS stealer via hidden commands and indirect prompt injection, weaponizing AI agents as unwitting malware intermediaries.
Product Idea from this Signal
A security layer that vets ClawHub skills for malware and prompt injection before your agent installs them
133.9k ▲SECURITYCLIDEVTOOLOPEN-SOURCE
CompetitiveView Opportunity →
Product Idea from this Signal
A CLI tool that scans a running OpenClaw instance for active CVEs, malicious skills, and supply chain tampering before they get exploited
807 ▲CLIOPEN-SOURCESECURITYDEVTOOLAUDIT
CompetitiveView Opportunity →
Product Idea from this Signal
A CLI security scanner that intercepts and blocks malicious ClawHub skills before they compromise your OpenClaw instance
183.8k ▲CLIOPEN-SOURCESECURITYDEVTOOL
Competitive75 leadsView Opportunity →
Social Proof 1 sources
Frequently Asked Questions
Virality Score
0
across 1 platforms
Details
Signalissue
Ecosystem—
Sources1
Platforms1
Updated21d ago
Trend→ stable
Top ideas
All ideas →Related signals
All signals →