
Ikhsan Rahardian
31.7K posts

Ikhsan Rahardian
@ixn
Tech, finance, & history - @facebook, @xenditco - 🇮🇩 in 🇮🇪







Whoa. This is truly unbelievable. This white hat is providing over-eager AI builders a much-needed wake up call. Jamieson built a backdoored Claude skill, inflated it to #1 on ClawdHub with 4,000+ fake downloads, then watched devs from all over the world execute what could have been malicious code, and direct access to... everything. SSH keys, AWS creds, .env files, you-name-it. Thankfully he just pinged a server to confirm his success. This is supply chain security 101 speedrun for the AI era. if you're building with AI agents, stop what you're doing and read this thread. Additionally, be sure to read Clawdbot's security documenatation and be sure to run `clawdbot doctor` regularly. Stay safe ✌️

Do NOT install any agentic browsers like OpenAI Atlas that just launched. Prompt injection attacks (malicious hidden prompts on websites) can easily hijack your computer, all your files and even log into your brokerage or banking using your credentials. Don’t be a guinea pig.





Claude now connects to your world on mobile. With your permission, Claude can find nearby spots, check your calendar, and schedule events—all without leaving the app.


AI agents that can browse the Web and perform tasks on your behalf have incredible potential but also introduce new security risks. We recently found, and disclosed, a concerning flaw in Perplexity's Comet browser that put users' accounts and other sensitive info in danger.














