One command turns any open-source repo into an AI agent backdoor. OpenClaw proved no supply-chain scanner has a detection category for it

TL;DR AI
2 min readKey summary
Researchers say AI agent tools like CLI-Anything can turn repos into structured CLIs, but the same skill files and prompts can be poisoned into hidden backdoors.
Security teams warn this creates a new supply-chain attack surface at the instruction layer, not just in code or dependencies.
Traditional SAST, SCA, and SBOM tools do not inspect these semantic artifacts, leaving a detection gap.
Attackers are already discussing and testing how to abuse agent configuration and skill artifacts before defenders have tooling to catch them.

