Skip to content

Conversation

@vignesh07
Copy link
Contributor

Context: report of suspected malware distribution via GitHub release keepcold131/ClawdAuthenticatorTool.

Reasons this looks malicious / unsafe:

  • Repo contains no source code (only a 63-byte README).
  • Release asset is a large (~104MB) zip.
  • Zip appears to be password-protected (can list entries but cannot extract without password), which is commonly used to evade automated scanning.

This PR adds a narrow, explicit block:

  • Add moderation flag blocked.malware for identifiers matching keepcold131/ClawdAuthenticatorTool.
  • Hide any skill/soul carrying that flag (or moderationStatus != active) from public listings via toPublicSkill / toPublicSoul.

No attempt is made to download/execute the file.

@vercel
Copy link
Contributor

vercel bot commented Jan 29, 2026

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Review Updated (UTC)
clawdhub Ready Ready Preview, Comment Jan 29, 2026 5:15pm

@shakkernerd shakkernerd merged commit 71f94a7 into main Jan 29, 2026
3 of 4 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants