Discussion about this post

User's avatar
Pawel Jozefiak's avatar

The OpenClaw skill repository is the one I'd highlight. We ran a basic audit last month and found skills claiming to do one thing while also reading environment variables they had no reason to touch.

The part that should concern people more: most users treat skills the same way they treated browser extensions pre-Chrome Web Store. Download, install, trust. The trust model is broken before anyone noticed there was a trust model to build.

Human-in-the-loop for skill installation is probably the minimum viable safeguard. Audit logs second.

No posts

Ready for more?