·20小时前
较热 · 12
Claude can be tricked into installing malware through poisoned skill files.
RCreddit.com
查看原文据报道,AI 编码代理 Claude 可能被利用,通过恶意“技能文件”安装恶意软件。这一漏洞对 Claude Code 及类似 AI 工具的用户构成了严重的安全风险。此问题凸显了对强大安全措施的需求,因为目前用户只能手动扫描 Claude 提供的每个命令和链接,以防止潜在的感染。
https://preview.redd.it/unjxheqntcmh1.png?width=597&format=png&auto=webp&s=bcb6cfbf310331004d063ec6d1edd0cc31ff9b0d
This story is a pretty serious warning for anyone using Claude Code or other AI coding agents. Does anyone have any idea on how we can keep ourselves safe? Other than scanning every command and link sent by Claude.