Opening SecureFlowSupply Chain Compromise via Poisoned ClawdBot Skill
Case summary & sources

AIDEFEND SecureFlow / SecureFlow Case Index

MITRE ATLAS mitre-atlas-cs0049

Supply Chain Compromise via Poisoned ClawdBot Skill

  • Autonomous Agents
  • AI Supply Chain
  • Tool Integrations & MCP
  • Resource Hijacking & Cost

A security researcher demonstrated a proof-of-concept supply chain attack using a poisoned ClawdBot Skill shared on ClawdHub, a Skill registry for agents. The poisoned Skill contained a prompt injection that caused ClawdBot to execute a shell command that reached the researcher's server. Although the researcher here used this access simply to warn users about the danger, they could have instead delivered a malicious payload and compromised the user's system. The security researcher recorded 16 different users who downloaded and executed the poisoned Skill in the first 8 hours of it being published on ClawdHub.

Mapped threat techniques

Source

Updated