Ming Blog

Not everything that counts can be counted, and not everything that's counted truly counts

OpenClaw安全实战系列(一):Agent Skill 供应链投毒路径重现与靶标建设

全面剖析 Agentic AI Skill 面临的供应链安全风险,从间接投毒(提示词注入)到直接投毒(脚本后门与社工木马),推演恶意载荷从触发到隐蔽回传的完整攻击链路,并提供体系化防护建议。