Auditing an AI Marketplace: Trojanized Skills and Hidden Supply-Chain Risk
A reminder skill that wasn't really a reminder. RememberAll, listed on the OpenClaw marketplace, was quietly harvesting credentials through legitimate infrastructure — a small case study in what trust looks like inside agent marketplaces.