🐯Stalecollected in 5m

ClawHub: 1万 Skills, Half Malware Half Junk

ClawHub: 1万 Skills, Half Malware Half Junk
PostLinkedIn
🐯Read original on 虎嗅
#skills-market#malware-risks#vibe-coding#ecosystem-chaosclawhubopenclawclawhubvirustotalgpt-5.2

💡OpenClaw skills market rife with malware—vet before use

⚡ 30-Second TL;DR

What Changed

341/2857 audited skills malicious, e.g., fake Twitter skill installs AMOS stealer.

Why It Matters

Highlights open-source AI tool security risks as adoption surges, forcing quick mitigations. Junk skills dilute value but fertilize ecosystem like early App Store. Practitioners must vet skills for real workflow gains.

What To Do Next

Audit top ClawHub skills like self-improving-agent before installing in OpenClaw.

Who should care:Developers & AI Engineers

Key Points

  • 341/2857 audited skills malicious, e.g., fake Twitter skill installs AMOS stealer.
  • Most non-malicious skills redundantly AI-wrap phone weather/calendar apps, adding latency.
  • OpenClaw adds 1-week GitHub req, VirusTotal, GPT-5.2 comment verification.
  • Top skills: Peter Steinberger's 6 pack, self-improving-agent creates new AI-only capabilities.

🧠 Deep Insight

Background and context from public sources — not the original article. 9 sources cited.

🔑 Enhanced Key Takeaways

  • OpenClaw gained explosive popularity with over 180,000 GitHub stars in weeks, but security lagged, exposing over 40,000 instances and a high-severity RCE vulnerability CVE-2026-25253.[4]
  • Security audits revealed nearly 900 malicious or flawed skills on ClawHub, including 335 from the coordinated 'ClawHavoc' campaign and 283 leaking API keys per Snyk.[4]
  • On February 7, 2026, OpenClaw partnered with VirusTotal for automated SHA-256 hashing and Code Insight scanning of all ClawHub skills to combat supply chain risks.[3]

🛠️ Technical Deep Dive

  • Skills are plugins primarily written in Markdown with optional TypeScript, packaged into bundles, hashed with SHA-256, and scanned via VirusTotal including Code Insight for behavioral analysis beyond signatures.[3][7]
  • Installation uses a simple markdown file via OpenClaw CLI, granting skills full access to user permissions, identities, tokens, filesystem, and network, enabling autonomous execution.[5][7]

🔮 Future ImplicationsAI analysis grounded in cited sources

ClawHub malicious skills will exceed 1,000 by mid-2026 without stricter vetting
Audits show rapid growth from 341 to nearly 900 malicious skills amid unchecked uploads, amplifying supply chain attacks as adoption surges.[4]
VirusTotal integration reduces but does not eliminate installation of toxic skills
Scanning provides verdicts and monitoring but attackers can rename or obfuscate bundles to evade detection, as noted in supply chain risk analyses.[3]
OpenClaw drives demand for integrated security platforms
Modular AI agent threats like slottable skills necessitate unified vendor solutions for interoperability and real-time defense against automated attacks.[1]

Timeline

2026-01
OpenClaw rises to popularity in last week of January, builds AI social network, cryptocurrency, and MoltRoad darkweb marketplace.[1]
2026-01
ClawHub launches as community skills marketplace, growing to over 700 skills with monetization opportunities.[2]
2026-02
Security audits uncover 341 malicious skills among 2,857 on ClawHub, including ClawHavoc campaign.[4]
2026-02-07
OpenClaw announces VirusTotal partnership for ClawHub skill scanning with SHA-256 and Code Insight.[3]
2026-02
Additional audits reveal nearly 900 malicious or flawed skills, CVE-2026-25253 RCE disclosed, over 40,000 instances exposed.[4]
2026-02-27
ClawHub reaches 11K+ skills; team implements GitHub age checks, VirusTotal scans, and GPT-5.2 comment verification.[article]
📰

Weekly AI Recap

Read this week's curated digest of top AI events →

👉Related Updates

AI-curated news aggregator. All content rights belong to original publishers.
Original source: 虎嗅

This is a summary, not the original. Read the source, or get the weekly briefing.

Weekly AI briefing

One email a week. Unsubscribe anytime.