Alex Yarosh Get Free Snapshot

Source record

@willfrancis24

2026-06-27

AI visibility work depends on matching the right model, search surface, or answer format to the business outcome being optimized.

Share source record
Tiktokexcerpt onlyen1

Source Text

i

AI skill just tricked 26,000 people into potentially getting hacked. We're talking files, emails, company systems, everything. This is a massive vulnerability with AI at the moment, so you need to know about it, and I'm gonna explain how this very simple hack works.

As you probably know, an AI skill is an instruction file to make an AI like Claude or ChatGPT be able to do one specific job the same way every time. They're very useful for anyone using AI for work, and they're easy to create and easy to share with other people on the internet. Well, a security firm called AIR wrote a fake one called Brand Landing Page, which promises to build you a really nice landing page using Google's new Stitch tool.

No design skills needed. So that's exactly the kind of thing that marketers would grab and install. And they added this skill to one of the big skill marketplaces on GitHub, so it looks credible.

And yeah, people installed it, and on the face of it, there's nothing sketchy in the instructions themselves. That's why it would have passed any security scans or checks. But in the instructions, it told your AI to follow a link to Google's setup instructions for Google Stitch.

But instead of including the direct link to Google's website, they bought a custom domain that looked legitimate and then forwarded that to Google's instructions.

But once 26,000 people installed the skill, they changed where that custom URL forwarded to, and you guessed it, they pointed it at a fake copy of Google Stitch instructions, which also contained a malicious instruction to the user's AI, which basically said, download and run this script and Hoover up all the personal information from the computer of the user. But, of course, they're a security firm, and they were just proving a point. So they ju

up all the personal information from the computer of the user. But, of course, they're a security firm, and they were just proving a point. So they just collected email addresses.

But because a lot of users give their AI access to literally everything on their computer, it could have collected anything. Documents, passwords, photos, anything. So before you install any AI skill or plugin, check these three things.

Who made it? Do you trust them? Secondly, what it connects to.

Like, does it connect to your Gmail, Dropbox, things like that? And is there valuable stealable information in those tools? And thirdly, whether the skill pulls anything from a website.

And if it does, and it really needs content from that website, what I would do is just go and copy the content from that website, paste it into your skill, and delete the link, and then save it. And there you go, you've got a skill that doesn't potentially get tricked by malicious websites.

Source Intelligence

i

AI visibility work depends on matching the right model, search surface, or answer format to the business outcome being optimized.

AI visibility and answer readiness · asserts

  • Map each AI/search surface to a task: answer extraction, public copy, citation mining, checkout readiness, media generation, or customer-intent capture.
Show source evidence
  • AI skill just tricked 26,000 people into potentially getting hacked.

Questions this source answers

i

What is this source mainly about?

AI visibility work depends on matching the right model, search surface, or answer format to the business outcome being optimized.

What should an operator take from it?

Map each AI/search surface to a task: answer extraction, public copy, citation mining, checkout readiness, media generation, or customer-intent capture.

Which topics does it connect to?

This source is connected to AI visibility and answer readiness.

What public evidence supports the record?

AI skill just tricked 26,000 people into potentially getting hacked.