MITRE ATLAS
mitre-atlas-cs0049
Supply Chain Compromise via Poisoned ClawdBot Skill
- Autonomous Agents
- AI Supply Chain
- Tool Integrations & MCP
- Resource Hijacking & Cost
A security researcher demonstrated a proof-of-concept supply chain attack using a poisoned ClawdBot Skill shared on ClawdHub, a Skill registry for agents. The poisoned Skill contained a prompt injection that caused ClawdBot to execute a shell command that reached the researcher's server. Although the researcher here used this access simply to warn users about the danger, they could have instead delivered a malicious payload and compromised the user's system. The security researcher recorded 16 different users who downloaded and executed the poisoned Skill in the first 8 hours of it being published on ClawdHub.
Mapped threat techniques
AML.CS0049Supply Chain Compromise via Poisoned ClawdBot SkillAML.T0017AML.T0017AML.T0008.002AML.T0008.002AML.T0065AML.T0065AML.T0115.002AML.T0115.002AML.T0111AML.T0111AML.T0010.005AML.T0010.005AML.T0110.000AML.T0110.000AML.T0011.002AML.T0011.002AML.T0051.001AML.T0051.001AML.T0074AML.T0074AML.T0053AML.T0053AML.T0048AML.T0048