ai-agent-supply-chain-attack

SkillSecurity

With this skill added, your AI can walk you through how AI and machine learning supply chain attacks happen, from poisoned models to compromised model registries. It covers model poisoning, Pickle-based code execution, Hugging Face and Ollama registry compromise, backdoored LangChain components, and threats to the OpenClaw and ClawHub ecosystems. It focuses on model weights, training data, and serialization formats, which sets it apart from CI/CD pipeline attacks.

Available today. Use it from your connected AI after setup.

Add the skill, then ask your AI about a specific AI supply chain risk, such as how a model registry compromise works, to get a grounded explanation of that threat.

Then ask your AI: use the ai-agent-supply-chain-attack skill

What your AI can do with it

  • Explain model poisoning and how training data can be tampered with
  • Recognize code execution risks in Pickle-serialized model files
  • Describe compromise scenarios for Hugging Face and Ollama registries
  • Identify backdoor patterns in LangChain components
  • Cover threats targeting the OpenClaw and ClawHub ecosystems
  • Separate AI supply chain threats from CI/CD pipeline attacks

Signals

GitHub stars
71
Forks
18
Last commit
Sep 2026
Advanced
Catalog kind
skill
Gateway key
ai-agent-supply-chain-attack
Source
github.com/brucesongs/kali-claw