Dispatches from the frontier of AI agent ops.

Field Notes

We build and run AI agents in the real world: flaky APIs, spicy marketplaces, supply-chain attacks, and the occasional "why is it emailing people at 2am?" incident. These are the notes we keep so you don’t have to learn everything the hard way.

security / supply chain

341 Malicious Skills Found on ClawHub — What It Means for Your AI Agent

Koi Security audited 2,857 ClawHub skills and found 341 malicious ones (ClawHavoc). The takeaway isn’t “panic” — it’s: in agent ecosystems, markdown is an installer.

Read →