ClawHub: 1万 Skills, Half Malware Half Junk

💡OpenClaw skills market rife with malware—vet before use
⚡ 30-Second TL;DR
What Changed
341/2857 audited skills malicious, e.g., fake Twitter skill installs AMOS stealer.
Why It Matters
Highlights open-source AI tool security risks as adoption surges, forcing quick mitigations. Junk skills dilute value but fertilize ecosystem like early App Store. Practitioners must vet skills for real workflow gains.
What To Do Next
Audit top ClawHub skills like self-improving-agent before installing in OpenClaw.
Key Points
- •341/2857 audited skills malicious, e.g., fake Twitter skill installs AMOS stealer.
- •Most non-malicious skills redundantly AI-wrap phone weather/calendar apps, adding latency.
- •OpenClaw adds 1-week GitHub req, VirusTotal, GPT-5.2 comment verification.
- •Top skills: Peter Steinberger's 6 pack, self-improving-agent creates new AI-only capabilities.
🧠 Deep Insight
Background and context from public sources — not the original article. 9 sources cited.
🔑 Enhanced Key Takeaways
- •OpenClaw gained explosive popularity with over 180,000 GitHub stars in weeks, but security lagged, exposing over 40,000 instances and a high-severity RCE vulnerability CVE-2026-25253.[4]
- •Security audits revealed nearly 900 malicious or flawed skills on ClawHub, including 335 from the coordinated 'ClawHavoc' campaign and 283 leaking API keys per Snyk.[4]
- •On February 7, 2026, OpenClaw partnered with VirusTotal for automated SHA-256 hashing and Code Insight scanning of all ClawHub skills to combat supply chain risks.[3]
🛠️ Technical Deep Dive
- •Skills are plugins primarily written in Markdown with optional TypeScript, packaged into bundles, hashed with SHA-256, and scanned via VirusTotal including Code Insight for behavioral analysis beyond signatures.[3][7]
- •Installation uses a simple markdown file via OpenClaw CLI, granting skills full access to user permissions, identities, tokens, filesystem, and network, enabling autonomous execution.[5][7]
🔮 Future ImplicationsAI analysis grounded in cited sources
⏳ Timeline
📎 Sources (9)
Factual claims are grounded in the sources below. Forward-looking analysis is AI-generated interpretation.
- security.com — Rise Openclaw
- marketingagent.blog — How to Use Openclaw AI for Marketing in 2026 a Complete Playbook
- penligent.ai — Openclaw Virustotal the Skill Marketplace Just Became a Supply Chain Boundary
- immersivelabs.com — Openclaw What You Need to Know Before It Claws Its Way Into Your Organization
- digitalocean.com — What Are Openclaw Skills
- esecurityplanet.com — Hundreds of Malicious Skills Found in Openclaws Clawhub
- permiso.io — Inside the Openclaw Ecosystem AI Agents with Privileged Credentials
- news.northeastern.edu — Open Claw AI Assistant
- Microsoft — Running Openclaw Safely Identity Isolation Runtime Risk
Weekly AI Recap
Read this week's curated digest of top AI events →
👉Related Updates
AI-curated news aggregator. All content rights belong to original publishers.
Original source: 虎嗅 ↗
This is a summary, not the original. Read the source, or get the weekly briefing.
Weekly AI briefing
One email a week. Unsubscribe anytime.


