JSJohn Smithinjohnspaghetti.hashnode.dev·Apr 1 · 7 min readI Ran SkillCompass on the Top 100 ClawHub Skills: Here's What I FoundTL’DR: One CRITICAL command injection flaw A supply-chain prompt injection risk ~199,000 installs exposed to documented vulnerabilities The most popular skill in the ecosystem has a near-failing s10
JSJohn Smithinjohnspaghetti.hashnode.dev·Mar 26 · 8 min readYour AI Agent is Failing. You Just Don’t Know Where.TL;DR: AI agent skills fail silently with wrong outputs, security gaps, and redundant logic, and the standard fix (rewrite the description, add examples, tweak instructions) usually targets the wrong 20