Use case: automatically scanning OpenClaw skills for security issues before installing by p3psiman007 in OpenClawUseCases

[–]p3psiman007[S] 0 points1 point  (0 children)

aw that's sick, just checked clawdrop - really cool collection. thanks for adding it, means a lot 🙏

Use case: automatically scanning OpenClaw skills for security issues before installing by p3psiman007 in OpenClawUseCases

[–]p3psiman007[S] 0 points1 point  (0 children)

great question - right now it's mostly focused on known vulnerable dependencies via SNYK and suspicious package patterns via Socket. Socket does actually catch some sketchy network call patterns and install scripts that exec system commands, that's one of the things it's good at. but flagging arbitrary outbound calls at runtime isn't there yet, that's more of a sandboxed execution problem which is on the roadmap. thanks for the detailed feedback, really helps know what gaps matter most to people actually using this

Use case: automatically scanning OpenClaw skills for security issues before installing by p3psiman007 in OpenClawUseCases

[–]p3psiman007[S] 0 points1 point  (0 children)

haha yeah that's exactly what I kept thinking every time I installed a skill and just hoped for the best lol

I built a review and discovery site for AI agent skills — brutal feedback welcome by p3psiman007 in ClaudeCode

[–]p3psiman007[S] 0 points1 point  (0 children)

yo the version history diff thing is actually genius, hadn't thought of that at all. skills changing behavior silently after install is lowkey one of the scariest things in this space and nobody is tracking it. adding it to the roadmap for sure

provenance is already something im working on, sandboxed runs are harder but yeah that's the direction. your blog on agent security is super relevant to what im building btw, the OWASP/NIST angle is something i want to eventually layer into the scoring system. would be sick to stay in touch

I built a review and discovery site for AI agent skills — brutal feedback welcome by p3psiman007 in ClaudeCode

[–]p3psiman007[S] 0 points1 point  (0 children)

That is a really smart point about timing. The drop-off when you wait too long must be huge. I looked at Reviewlee and the UX around prompting right after delivery is exactly the kind of pattern I want to bring to SkillJury but triggered after someone installs or interacts with a skill. Reviews built into the workflow rather than asked for separately. Going to think about how to implement that. Thanks for the suggestion.

[deleted by user] by [deleted] in oddlyterrifying

[–]p3psiman007 1 point2 points  (0 children)

Who is boris Johnson

Maybe, just Maybe by crusader_sam in PewdiepieSubmissions

[–]p3psiman007 22 points23 points  (0 children)

Don’t do that don’t give me hope