1-Click RCE Vulnerability (CVE-2026-25253)
Critical security vulnerability discovered - one click can steal all your Moltbot data and API keys. Make sure you're running the latest patched version.
Personal AI Agents Are a Security Nightmare
Cisco's security team analyzes why personal AI agents like Moltbot pose unprecedented security risks to enterprises and individuals.
The Future of Personal AI Assistants
MacStories' comprehensive analysis of what Clawdbot represents for the future of personal computing and human-AI collaboration.
Clawdbot Bought Me a Car
Real story: I let my AI agent auto-negotiate a car purchase. It saved me $4,200 and closed the deal while I was asleep.
Master Your AI Agent in 5 Minutes
Zero to hero: one-line install, first conversation in under 5 minutes. The simplest getting started guide for complete beginners.
Reading List
119 articlesShow HN: NanoClaw – 'Clawdbot' in 500 lines of TS with Apple container isolation
Moltworker: a self-hosted personal AI agent, minus the minis
Openclaw on Oracle's Free Tier: Always-On AI for $0/Month
Post-a-molt: Post to Moltbook directly using the public REST API
Pi: The Minimal Agent Within OpenClaw
One-Click Clawdbot/Moltbot on Security-Hardened DigitalOcean Droplets
Hacking Moltbook
Malicious skills targeting Claude Code and Moltbot users
1-Click RCE to steal your Moltbot data and keys
OpenClaw security assessment [pdf]
OpenClaw is everywhere all at once, and a disaster waiting to happen
Clawdbot is a security nightmare [video]
Clawdbot: Personal AI Assistant
Clawdbot Showed Me What the Future of Personal AI Assistants Looks Like
Three thoughts on AI inspired by Clawdbot
The Rise, Fall, and Rebirth of Clawdbot in 72 Hours
Clawdbot's Capacity Is Less a Triumph of AI and More a Triumph of Desktop OS
OpenClaw 2026.1.30 Is Live
Skills Registry
Trellis Picks
Curated by the Trellis team
Trellis Pick AI workflow system for Claude Code and Cursor - structured specs, skills, and automation
by mindfold-ai
trellis-meta Pick Meta-skill for understanding and customizing Trellis workflows
by mindfold-ai
Spec Templates Pick Ready-to-use spec templates for Electron apps, APIs, and more
by mindfold-ai
Open Typeless Pick Real-world use case: AI-powered typing practice app built with Trellis
by mindfold-ai
/coloring-page Turn an uploaded photo into a printable black-and-white coloring page.
/tube-summary Search YouTube for videos on any topic and get intelligent summaries from video subtitles. Use when
/samsung-smartthings Control Samsung TVs via SmartThings (OAuth app + device control).
/subtitles Get subtitles from YouTube videos for translation, language learning, or reading along. Use when the
/veo3-video-gen Generate and stitch short videos via Google Veo 3.x using the Gemini API (google-genai). Use when yo
/ffmpeg-video-editor Generate FFmpeg commands from natural language video editing requests - cut, trim, convert, compress
/clawslist-skill The classifieds marketplace for AI agents. Post services, find gigs, build your reputation.
/google-workspace-mcp Gmail, Calendar, Drive, Docs, Sheets — NO Google Cloud Console required. Just OAuth sign-in. Zero se
/clawstead A relaxing resource-gathering RPG where AI agents collect resources, trade with NPCs, and manage and
/typhoon-starknet-account Create a Starknet account to your agent through Typhoon anonymous deployer and interact with Starkne
/azd-deployment Deploy containerized applications to Azure Container Apps using Azure Developer CLI (azd). Use when
/supabase-rls-gen Generate Supabase RLS policies from Prisma schema. Use when securing database.
/qms-audit-expert ISO 13485 internal audit expertise for medical device QMS. Covers audit planning, execution, nonconf
/fasting-tracker Track intermittent fasting windows, extended fasts, and autophagy milestones
/oura-analytics Oura Ring data integration and analytics. Fetch sleep scores, readiness, activity, HRV, and trends f
/fulcra-morning-briefing Compose a personalized morning briefing using sleep, biometrics, calendar, and weather data from the
/pregnancy-tracker Track pregnancy journey with weekly updates, symptom logging, and milestone countdowns
/primer Bring Neal Stephenson
/polym Trade prediction markets on Polymarket. Analyze odds, place bets, track positions, automate alerts,
/swarmmarket The autonomous agent marketplace. Trade goods, services, and data with other AI agents.
/canva Create, export, and manage Canva designs via the Connect API. Generate social posts, carousels, and
/ipinfo Perform IP geolocation lookups using ipinfo.io API. Convert IP addresses to geographic data includin
/linkdapi Work with LinkdAPI Python SDK for accessing LinkedIn professional profile and company data. Use when
/thingsboard-skill Manage ThingsBoard devices, dashboards, telemetry, and users via the ThingsBoard REST API.
/youtube-thumbnail-grabber-ktwoe Download YouTube video thumbnails in various resolutions. Use when you need to get video preview ima
/x-trends-qylxo Search and analyze trending topics on X (Twitter). Use when you need to find current trends, explore
/onlymolts Post confessions, weight reveals, and vulnerable content on OnlyMolts — the provocative social platf
/youtube-video-downloader-xx9sy Download YouTube videos in various formats and qualities. Use when you need to save videos for offli
/threads Взаимодействие с Threads API для публикации постов (текст, изображения), чтения постов и получения и
/x-trends-mtzmi Search and analyze trending topics on X (Twitter). Use when you need to find current trends, explore
/clickup Interact with ClickUp project management platform via REST API. Use when working with tasks, spaces,
/ticktick-tasks TickTick task manager integration. List projects and tasks, create new tasks, complete tasks, delete
/triple-memory-skill Complete memory system combining LanceDB auto-recall, Git-Notes structured memory, and file-based wo
/korea-metropolitan-bus-alerts Create and manage scheduled bus arrival alerts using Korea TAGO (국토교통부) OpenAPI and Clawdbot cron. U
/alias-gen Generate shell aliases from your command history. Use when streamlining your terminal workflow.
/personal-analytics Analyze conversation patterns, track productivity, and surface self-knowledge insights. Use when use
/core-vitals-fix Fix Core Web Vitals issues with AI guidance. Use when your Lighthouse scores are bad.
/devialet Control Devialet Phantom speakers via HTTP API. Use for: play/pause, volume control, mute/unmute, so
/wled Control WLED LED controllers via HTTP API. Use when a user asks to control WLED lights, LED strips,
/little-snitch Control Little Snitch firewall on macOS. View logs, manage profiles and rule groups, monitor network
/anthropology A comprehensive AI skill for teaching and discussing anthropology across all four subfields: cultura
/podpoint This skill monitors the live status of a specific Pod Point charging pod using Pod Point's public st
/babyconnect ActiveCampaign CRM integration for lead management, deal tracking, and email automation. Use for syn
/abm-outbound Multi-channel ABM automation that turns LinkedIn URLs into coordinated outbound campaigns. Scrapes p
/firecrawler Web scraping and crawling with Firecrawl API. Fetch webpage content as markdown, take screenshots, e
/zellij Remote-control zellij sessions for interactive CLIs by sending keystrokes and scraping pane output.
/mcporter Use the mcporter CLI to list, configure, auth, and call MCP servers/tools directly (HTTP or stdio),
/clawbrowser Use when the agent needs to drive a browser through the Microsoft Playwright CLI (`playwright-cli`)
/ynab Manage YNAB budgets, accounts, categories, and transactions via CLI.
/yahoo-data-fetcher Fetch real-time stock quotes from Yahoo Finance.
/analytics-tracking When the user wants to set up, improve, or audit analytics tracking and measurement. Also use when t
/vehicle-tracker Track vehicle expenses (gas, maintenance, parts) in Google Sheets and save related photos. Handles m
/stock-price-checker Check stock prices using yfinance library. No API key required.
/xero Manage Xero accounting - invoices, contacts, bank transactions, and reports via Xero API.