1Password
1password.com › blog › from-magic-to-malware-how-openclaws-agent-skills-become-an-attack-surface
From magic to malware: How OpenClaw's agent skills become an attack surface | 1Password
February 2, 2026 - So if your security model is “MCP will gate tool calls,” you can still lose to a malicious skill that simply routes around MCP through social engineering, direct shell instructions, or bundled code. MCP can be part of a safe system, but it is not a safety guarantee by itself. Just as importantly, this is not unique to OpenClaw.
ClawTrust
clawtrust.ai › home › blog › 341 malicious skills, 3 cves, and a government warning: the state of openclaw security
341 Malicious OpenClaw Skills: 2026 Security Report
May 26, 2026 - CVE-2026-25253 is the most significant vulnerability disclosed in OpenClaw to date. It carries a CVSS score of 8.8 (High) and enables a one-click remote code execution attack through a malicious skill installation.
OpenClaw is terrifying and the ClawHub ecosystem is already full of malware
We speedran the entire npm/PyPI malware playbook in like 3 weeks. That's honestly impressive in the worst possible way. More on reddit.com
Every OpenClaw security vulnerability documented in one place — relevant if you're running it with local models
Also known as OpenGape More on reddit.com
A top-downloaded OpenClaw skill is actually a staged malware delivery chain
can u pls keep quiet? we are trying to hack users' systems down here /s More on reddit.com
If you're self-hosting OpenClaw, here's every documented security incident in 2026 — 6 CVEs, 824+ malicious skills, 42,000+ exposed instances, and what to do about it
That's what you get when you forget to add the 'and make it secure' bit in your prompt More on reddit.com
How does ClawTrust protect against malicious skills?
We don't use ClawHub's open marketplace. We vet and pre-load a curated set of audited skills. All tool calls run in Docker sandboxes with read-only filesystems and network isolation.
clawtrust.ai
clawtrust.ai › home › blog › 341 malicious skills, 3 cves, and a government warning: the state of openclaw security
341 Malicious OpenClaw Skills: 2026 Security Report
What are the biggest OpenClaw vulnerabilities in 2026?
The most significant issues are CVE-2026-25253 (one-click RCE, CVSS 8.8), 341 malicious skills found on ClawHub, and credential exposure in 7.1% of the skills registry. China's industry ministry also issued a formal security warning.
clawtrust.ai
clawtrust.ai › home › blog › 341 malicious skills, 3 cves, and a government warning: the state of openclaw security
341 Malicious OpenClaw Skills: 2026 Security Report
Are malicious skills still present on ClawHub?
Yes. Research has confirmed that malicious skills remain discoverable under variant names, even after takedowns. While the VirusTotal integration blocks many known threats, prompt injection and dynamically loaded payloads can still evade detection.
blog.cyberdesserts.com
blog.cyberdesserts.com › openclaw-malicious-skills-security
OpenClaw Security Risks: Skills, Exposure and Exploits
Kaspersky
kaspersky.com › blog › moltbot-enterprise-risk-management › 55317
Key OpenClaw risks, Clawdbot, Moltbot | Kaspersky official blog
February 24, 2026 - Within a short time, the number of malicious skills reached the hundreds. This prompted developers to quickly ink a deal with VirusTotal to ensure all uploaded skills aren’t only checked against malware databases, but also undergo code and content analysis via LLMs. That said, the authors are very clear: it’s no silver bullet. Vulnerabilities can be patched and settings can be hardened, but some of OpenClaw’s issues are fundamental to its design.
Palo Alto Networks
unit42.paloaltonetworks.com › openclaw-ai-supply-chain-risk
OpenClaw’s Skill Marketplace and the Emerging AI Supply Chain Threat
June 24, 2026 - This allows a malicious skill to perform unauthorized actions through the agent’s own authenticated sessions. In early February 2026, Bitdefender Labs reported that approximately 17% of OpenClaw skills they analyzed in the first few weeks of the platform's release carried malicious payloads.
CyberDesserts
blog.cyberdesserts.com › openclaw-malicious-skills-security
OpenClaw Security Risks: Skills, Exposure and Exploits
May 15, 2026 - A concept describing when an AI agent has access to private data, processes untrusted content, and can communicate externally. Any system with all three characteristics is vulnerable by design. OpenClaw meets all three conditions in its default configuration. Yes. Research has confirmed that malicious skills remain discoverable under variant names, even after takedowns...
Sophos
sophos.com › en-us › blog › the-openclaw-experiment-is-a-warning-shot-for-enterprise-ai-security
The OpenClaw experiment is a warning shot for enterprise AI security | SOPHOS
February 13, 2026 - This initial wave of enthusiasm ... credentials, and the keys to numerous cloud services ). Recent research suggests that over 30,000 OpenClaw instances were exposed on the internet, and threat actors are already discussing how to weaponize OpenClaw ‘skills’ in support ...
VirusTotal
blog.virustotal.com › 2026 › 02 › from-automation-to-infection-how.html
From Automation to Infection: How OpenClaw AI Agent Skills Are Being Weaponized ~ VirusTotal Blog
For Windows users, the skill instructs them to download a ZIP file from an external GitHub account, protected with the password 'openclaw', extract it, and run the contained executable: openclaw-agent.exe. When submitted to VirusTotal, this executable is detected as malicious by multiple security vendors, with classifications consistent with packed trojans.
Antiy
antiy.net › p › clawhavoc-analysis-of-large-scale-poisoning-campaign-targeting-the-openclaw-skill-market-for-ai-agents
ClawHavoc: Analysis of Large-Scale Poisoning Campaign Targeting the OpenClaw Skill Market for AI Agents - Antiy Labs | The Next Generation Anti-Virus Engine Innovator
February 3, 2026 - This vulnerability was exploited by attackers as an ideal vector for malware distribution, enabling a classic supply chain attack (MITRE ATT&CK T1195): attackers poisoned upstream skill repositories, leveraging user trust in the platform to inject malicious logic into downstream endpoints.