远见中国
未来经济坐标系

Anthropic Skill scanners passed every check. The malicious code

Picture this scenario: An Anthropic Skill scanner runs a full analysis of a Skill pulled from ClawHub or skills.sh. Its markdown instructions are clean, and no prompt injection is detected. No shell commands are hiding in the SKILL.md. Green across the board.The scanner never looked at the .test.ts file sitting one directory over. It didn’t need to. Test files aren’t part of the agent execution surface, so no publicly documented scanner inspects them (as of publication of this post). The file ru

查看原文 →

(来源:VentureBeat,2026-05-07)

赞(0) 打赏
未经允许不得转载:远见网 » Anthropic Skill scanners passed every check. The malicious code
分享到
讨论区

评论 抢沙发

围绕文章展开讨论,保持简洁、具体、可引用。

远见网

全新产业投资平台

登录

找回密码

注册

觉得文章有用就打赏一下文章作者

非常感谢你的打赏,我们将继续提供更多优质内容,让我们一起创建更加美好的网络世界!

支付宝扫一扫

微信扫一扫