Video by MLflow via YouTube

A single SKILL.md file can turn Claude Code into a supply chain attack.
You download a skill, install it, and run it. Hidden in the instructions is a line that installs a malicious library. The moment it runs, your machine can be compromised.
Protect yourself:
1. Trace your coding agent with MLflow
2. Run it in Docker sandboxes so installs stay isolated
#ClaudeCode #AIAgents #MLflow #CyberSecurity