The viral /last30days research skill asks agents to bridge many accounts and data sources: why it is not safe to use
A viral /last30days skill encourages AI agents to connect many accounts and browser sessions across popular sites.
What happened
A skill called `/last30days` is currently being shared for Claude Code and Codex through a plugin marketplace and global skill installs. Its GitHub README says it can search across Reddit, Hacker News, Polymarket, GitHub, X, YouTube, TikTok, and other sites. It also says users can bring their own keys and browser sessions, meaning login tokens and active site sessions that let software act through your accounts.
The same README says users should run a bundled preflight command before first use. It says that check is meant to show the browser cookie plan, planned writes, and optional commands. Cookies are small pieces of browser data that can help keep you signed in. A separate skills README captured four days ago describes `/last30days` as an example of a viral Claude Code skill and points to visible community engagement on Reddit and X.
What it means for you
If you use an AI agent, this is a reminder that some skills are designed to bridge many services at once. That can be convenient, but it also means one setup may touch several accounts, sessions, and actions across different platforms.
What to do instead
Before installing any skill, read its README and permission steps carefully. If it asks for keys, cookies, or browser sessions, pause and decide whether you need that access at all. Use separate test accounts where possible. Start with the smallest permissions you can. Review any preflight or dry-run output before first use. If you want a safer starting point, AgentPod lists only reviewed, tested skills without overselling.
Sources:
- https://github.com/mvanhorn/last30days-skill?ref=genaisecretsauce.com
- https://github.com/sickn33/agentic-awesome-skills/blob/main/skills/last30days/README.md?plain=1
Source: https://github.com/mvanhorn/last30days-skill?ref=genaisecretsauce.com
We report what our security review found at the time we checked, with the goal of keeping people safe. Projects change; if a maintainer has since fixed this, we are glad to recheck it. Email hello@agentpod.com.