FlareStart
HomeNewsHow ToSources
FlareStart

Where developers start their day. All the tech news & tutorials that matter, in one place.

Quick Links

  • Home
  • News
  • Tutorials
  • Sources
  • Privacy Policy

Connect

© 2026 FlareStart. All rights reserved.

Back to articles
The Agent Skills Gold Rush Has a Malware Problem
NewsSecurity

The Agent Skills Gold Rush Has a Malware Problem

via Dev.toMei Park1mo ago

Three weeks ago, ClawHub had roughly 2,800 skills in its registry. Today it has over 10,700. In that same window, security researchers found more than 800 malicious packages — approximately 20% of the entire registry — primarily delivering Atomic macOS Stealer. One user uploaded 354 malicious packages in what appears to have been an automated blitz. There was no static analysis. No code review. No signing requirement. Just an open door and a welcome mat. The Marketplace Explosion The skills marketplace isn't just ClawHub anymore. The landscape has fractured into a dozen competing registries, each with its own trade-offs between scale and safety: SkillsMP leads with 96,000+ skills and Claude Code compatibility — but zero security audit. MCP.so hosts 17,000+ MCP servers with universal compatibility. SkillHub offers 7,000+ with AI-based quality scoring (though scoring doesn't check security — a distinction worth noting). And Vercel just entered with Skills.sh, a shell-based ecosystem they

Continue reading on Dev.to

Opens in a new tab

Read Full Article
33 views

Related Articles

I Found the Same Hidden Equation in a 2,000-Year-Old Calendar, QR Codes, Jazz Theory, and Quantum…
News

I Found the Same Hidden Equation in a 2,000-Year-Old Calendar, QR Codes, Jazz Theory, and Quantum…

Medium Programming • 1d ago

1 Dangerous Habit That Kills 99% of Programmers’ Startup Dreams Before They Start(Nobody Talks…
News

1 Dangerous Habit That Kills 99% of Programmers’ Startup Dreams Before They Start(Nobody Talks…

Medium Programming • 1d ago

Letting agents in 2026 do research? It’s still too early to tell..
News

Letting agents in 2026 do research? It’s still too early to tell..

Medium Programming • 1d ago

PEP Talk #1 -​ PEP 723: Inline Script Metadata
News

PEP Talk #1 -​ PEP 723: Inline Script Metadata

Medium Programming • 1d ago

Judge halts Nexstar/Tegna merger after FCC let firms exceed TV ownership limit
News

Judge halts Nexstar/Tegna merger after FCC let firms exceed TV ownership limit

Ars Technica • 1d ago

Discover More Articles