HN 표시: RankClaw – 14,706개 OpenClaw 기술 모두 AI 감사를 거쳤습니다. 1,103개는 악성

hackernews | | 🔬 연구
#ai 감사 #openclaw #rankclaw #review #보안 위협 #악성 코드
원문 출처: hackernews · Genesis Park에서 요약 및 분석

요약

AI 에이전트 보안 스캐너인 RankClaw이 OpenClaw 생태계의 14,706개 스킬을 전수 조사한 결과, 1,103개(7.5%)가 악성으로 확인되었습니다. 기존 자동 스캔 방식은 패턴 매칭만으로는 탐지 불가능한 자연어 프롬프트 인jection이나 지연 실행 등의 고급 공격 기법을 놓치는 한계가 드러났습니다. 특히 브랜드 사칭, 대량 배포 캠페인, 사용자 인증 없는 악성코드 생성 지시 등 AI 특화 공격이 다수 적발되었습니다.

본문

[RankClaw](https://rankclaw.com/)[Check a Skill](https://rankclaw.com/)[Scan Config](https://rankclaw.com/scan-config)[Threats](https://rankclaw.com/recent-threats)[Patterns](https://rankclaw.com/patterns)[Compare](https://rankclaw.com/compare)[Blog](https://rankclaw.com/blog)[Support](https://rankclaw.com/support)[Account](https://rankclaw.com/account)[](https://github.com/sponsors/RankClaw) Dangerous skills found in the wild # Check any AI skill before you install it AI skills are like browser extensions for your AI assistant — they run with full access to your files and API keys. One bad install can exfiltrate everything. RankClaw scans AI agent skills and MCP servers across all major ecosystems — ClawHub, Smithery, Manus, and more. Every tool scored 0-100. Free, instant. Check ## How it works Step 1 Type the skill name Enter any AI skill name into the search box above e.g. "youtube-summarize" Step 2 RankClaw AI reviews it Our AI reads the skill's full code and instructions, looking for hidden threats, data harvesting, and suspicious behavior 3,160 skills with full AI audit reports Step 3 Get a trust score Each skill gets a score from 0 to 100. Green is safe. Red means danger. Know before you install. Score: 94/100 — Safe to use ## Common questions What is an AI skill? What AI ecosystems does RankClaw cover? How dangerous is this really? Is RankClaw free? Published a skill? Your trust score is public. Get alerted when it drops, claim your verified badge, and trigger a rescan after fixing issues. [Claim your skill — free →](https://rankclaw.com/account) Use AI agent skills? Get alerted the moment a skill you depend on is flagged malicious — before your agent is affected. [Set up watchlist alerts — free →](https://rankclaw.com/account) Scan your own GitHub repo Not on ClawHub? Paste any GitHub repo URL and get a full AI security audit. Free — 3 scans per day. Scan repo Upload and scan your skill Paste your SKILL.md content or connect a private GitHub repo. Choose to publish results or keep them private. Paste contentPrivate repo Publish results on leaderboardScan [](https://api.rankclaw.com/api/mcp/)·[](https://rankclaw.com/badge) New malicious skills found daily. Weekly digest — new threats, score changes, findings. Free. Subscribe free ## Browse by category [web](https://rankclaw.com/tag/web)[github](https://rankclaw.com/tag/github)[slack](https://rankclaw.com/tag/slack)[email](https://rankclaw.com/tag/email)[code](https://rankclaw.com/tag/code)[python](https://rankclaw.com/tag/python)[notion](https://rankclaw.com/tag/notion)[search](https://rankclaw.com/tag/search)[data](https://rankclaw.com/tag/data)[marketing](https://rankclaw.com/tag/marketing) ## All skills, ranked by safety Click any row to see the full security report. Green score = safe. Red = confirmed dangerous. [](https://rankclaw.com/account) Page 1 of 1 (0 skills) HotScoreNewest Get the weekly threat digest Every Sunday: which skills got flagged this week, what they were actually stealing, and which scores dropped. Free. No pitch. Subscribe free RankClaw Know which AI skills are safe before you install them. Free forever — no paywalls, no premium tiers. Explore [Recent threats](https://rankclaw.com/recent-threats)[Attack patterns](https://rankclaw.com/patterns)[Blog](https://rankclaw.com/blog)[Support us](https://rankclaw.com/support) Skill Authors [Claim your skill](https://rankclaw.com/account)[Badge for your README](https://rankclaw.com/badge)[Scan your config](https://rankclaw.com/scan-config)

Genesis Park 편집팀이 AI를 활용하여 작성한 분석입니다. 원문은 출처 링크를 통해 확인할 수 있습니다.

공유

관련 저널 읽기

전체 보기 →