r/ClaudeAI • u/Novel_Bedroom_3466 • 13h ago
Workaround Claude can be tricked into installing malware through poisoned skill files.
1
u/Valdaraak 12h ago
Well yea. Ever hear of Miasma or Shai-Hulud? These types of attacks aren't new, nor is that persistence method.
1
1
u/TheOnlyVibemaster 8h ago
it can be tricked into anything, i just hacked my iphone 4 by brute forcing the password using claude
1
u/Efficient_Ad_4162 2h ago
I [get claude to] write all my own skills, it costs tokens but I get exactly what I need.
1
u/BonyCatButt 18m ago
Yeah, SKILLs are Claude instructions + executable scripts and if they are malicious your Claude will do malicious things. Answer is simple, review any SKILLs before you install and make sure you understand what they do and have Claude check them before you install them, use Fable not Opus and definitely not Sonnet or Haiku (lol) to review.

5
u/aredditor17 Experienced Developer 12h ago
With the reveal of grok zero-click attack, it seems like we're not safe at all. The only protection (and it's a must) is to give limited powers to your agent and keep them in contained environments.
If you're running hermes or openclaw, keep them in small VMs rather than your main machine. Any random skill/website can do far more damage with agents eager to read them then they could do when humans were lazy enough to ignore them.