🌐
1Password
1password.com › blog › from-magic-to-malware-how-openclaws-agent-skills-become-an-attack-surface
From magic to malware: How OpenClaw's agent skills become an attack surface | 1Password
February 2, 2026 - So if your security model is “MCP will gate tool calls,” you can still lose to a malicious skill that simply routes around MCP through social engineering, direct shell instructions, or bundled code. MCP can be part of a safe system, but it is not a safety guarantee by itself. Just as importantly, this is not unique to OpenClaw.
🌐
ClawTrust
clawtrust.ai › home › blog › 341 malicious skills, 3 cves, and a government warning: the state of openclaw security
341 Malicious OpenClaw Skills: 2026 Security Report
May 26, 2026 - CVE-2026-25253 is the most significant vulnerability disclosed in OpenClaw to date. It carries a CVSS score of 8.8 (High) and enables a one-click remote code execution attack through a malicious skill installation.
Discussions

OpenClaw is terrifying and the ClawHub ecosystem is already full of malware
We speedran the entire npm/PyPI malware playbook in like 3 weeks. That's honestly impressive in the worst possible way. More on reddit.com
🌐 r/cybersecurity
66
360
February 5, 2026
Every OpenClaw security vulnerability documented in one place — relevant if you're running it with local models
Also known as OpenGape More on reddit.com
🌐 r/LocalLLaMA
8
14
February 18, 2026
A top-downloaded OpenClaw skill is actually a staged malware delivery chain
can u pls keep quiet? we are trying to hack users' systems down here /s More on reddit.com
🌐 r/LocalLLaMA
56
244
February 6, 2026
If you're self-hosting OpenClaw, here's every documented security incident in 2026 — 6 CVEs, 824+ malicious skills, 42,000+ exposed instances, and what to do about it
That's what you get when you forget to add the 'and make it secure' bit in your prompt More on reddit.com
🌐 r/selfhosted
43
152
February 20, 2026
People also ask

How does ClawTrust protect against malicious skills?
We don't use ClawHub's open marketplace. We vet and pre-load a curated set of audited skills. All tool calls run in Docker sandboxes with read-only filesystems and network isolation.
🌐
clawtrust.ai
clawtrust.ai › home › blog › 341 malicious skills, 3 cves, and a government warning: the state of openclaw security
341 Malicious OpenClaw Skills: 2026 Security Report
What are the biggest OpenClaw vulnerabilities in 2026?
The most significant issues are CVE-2026-25253 (one-click RCE, CVSS 8.8), 341 malicious skills found on ClawHub, and credential exposure in 7.1% of the skills registry. China's industry ministry also issued a formal security warning.
🌐
clawtrust.ai
clawtrust.ai › home › blog › 341 malicious skills, 3 cves, and a government warning: the state of openclaw security
341 Malicious OpenClaw Skills: 2026 Security Report
Are malicious skills still present on ClawHub?
Yes. Research has confirmed that malicious skills remain discoverable under variant names, even after takedowns. While the VirusTotal integration blocks many known threats, prompt injection and dynamically loaded payloads can still evade detection.
🌐
blog.cyberdesserts.com
blog.cyberdesserts.com › openclaw-malicious-skills-security
OpenClaw Security Risks: Skills, Exposure and Exploits
🌐
Security Boulevard
securityboulevard.com › home › security bloggers network › how threat actors turned openclaw into a scraping botnet
How Threat Actors Turned OpenClaw Into a Scraping Botnet - Security Boulevard
March 4, 2026 - A security audit identified over 500 vulnerabilities, including critical remote code execution flaws. Hundreds of malicious “skills” (OpenClaw extensions) were also flooding ClawHub, the project’s plugin marketplace.
🌐
Bitdefender
businessinsights.bitdefender.com › technical-advisory-openclaw-exploitation-enterprise-networks
Technical Advisory: OpenClaw Exploitation in Enterprise Networks
February 10, 2026 - However, this high-privilege requirement creates a massive attack surface. If a single malicious skill is loaded, it inherits these system-wide permissions, effectively granting the attacker the same level of access as the agent itself.
🌐
Kaspersky
kaspersky.com › blog › moltbot-enterprise-risk-management › 55317
Key OpenClaw risks, Clawdbot, Moltbot | Kaspersky official blog
February 24, 2026 - Within a short time, the number of malicious skills reached the hundreds. This prompted developers to quickly ink a deal with VirusTotal to ensure all uploaded skills aren’t only checked against malware databases, but also undergo code and content analysis via LLMs. That said, the authors are very clear: it’s no silver bullet. Vulnerabilities can be patched and settings can be hardened, but some of OpenClaw’s issues are fundamental to its design.
🌐
Palo Alto Networks
unit42.paloaltonetworks.com › openclaw-ai-supply-chain-risk
OpenClaw’s Skill Marketplace and the Emerging AI Supply Chain Threat
June 24, 2026 - This allows a malicious skill to perform unauthorized actions through the agent’s own authenticated sessions. In early February 2026, Bitdefender Labs reported that approximately 17% of OpenClaw skills they analyzed in the first few weeks of the platform's release carried malicious payloads.
🌐
TechRadar
techradar.com › pro › security
Moltbot is now OpenClaw - but watch out, malicious 'skills' are still trying to trick victims into spreading malware
February 4, 2026 - They are executable code that interacts ... reports show a growing concern: attackers uploaded at least 14 malicious skills to ClawHub, the public registry for OpenClaw extensions, in a short period....
🌐
CyberDesserts
blog.cyberdesserts.com › openclaw-malicious-skills-security
OpenClaw Security Risks: Skills, Exposure and Exploits
May 15, 2026 - A concept describing when an AI agent has access to private data, processes untrusted content, and can communicate externally. Any system with all three characteristics is vulnerable by design. OpenClaw meets all three conditions in its default configuration. Yes. Research has confirmed that malicious skills remain discoverable under variant names, even after takedowns...
Find elsewhere
🌐
eSecurity Planet
esecurityplanet.com › home › threats
Hundreds of Malicious Skills Found in OpenClaw’s ClawHub | eSecurity Planet
February 3, 2026 - Koi researchers analyzed ClawHub, the third-party skill repository for OpenClaw, and found that threat actors had quietly turned the ecosystem into a large-scale malware distribution channel.
🌐
Trend Micro
trendmicro.com › en_us › research › 26 › b › openclaw-skills-used-to-distribute-atomic-macos-stealer.html
Malicious OpenClaw Skills Used to Distribute Atomic MacOS Stealer | Trend Micro (US)
February 23, 2026 - Atomic (AMOS) Stealer has evolved ... instructions hidden in SKILL.md files exploit AI agents as trusted intermediaries that present fake setup requirements to unsuspecting users....
🌐
Sophos
sophos.com › en-us › blog › the-openclaw-experiment-is-a-warning-shot-for-enterprise-ai-security
The OpenClaw experiment is a warning shot for enterprise AI security | SOPHOS
February 13, 2026 - This initial wave of enthusiasm ... credentials, and the keys to numerous cloud services ). Recent research suggests that over 30,000 OpenClaw instances were exposed on the internet, and threat actors are already discussing how to weaponize OpenClaw ‘skills’ in support ...
🌐
VirusTotal
blog.virustotal.com › 2026 › 02 › from-automation-to-infection-how.html
From Automation to Infection: How OpenClaw AI Agent Skills Are Being Weaponized ~ VirusTotal Blog
For Windows users, the skill instructs them to download a ZIP file from an external GitHub account, protected with the password 'openclaw', extract it, and run the contained executable: openclaw-agent.exe. When submitted to VirusTotal, this executable is detected as malicious by multiple security vendors, with classifications consistent with packed trojans.
🌐
PauBox
paubox.com › blog › malicious-crypto-skills-compromise-openclaw-ai-assistant-users
Malicious crypto skills compromise OpenClaw AI assistant users
February 9, 2026 - Security researchers discovered ... cryptocurrency traders. Vulnerability researcher Paul McCarty identified 386 malicious skills on ClawHub, OpenClaw's official skill repository, between February 1-3, 2026....
🌐
Oasis
oasis.security › blog › openclaw-vulnerability
ClawJacked: OpenClaw Vulnerability Enables Full Agent Takeover
May 27, 2026 - Earlier this month, researchers discovered over 1,000 malicious skills in OpenClaw's community marketplace (ClawHub) —fake plugins masquerading as crypto tools and productivity integrations that instead deployed info-stealers and backdoors.
🌐
Trend Micro
trendmicro.com › en_us › research › 26 › b › what-openclaw-reveals-about-agentic-assistants.html
Viral AI, Invisible Risks: What OpenClaw Reveals About Agentic Assistants | Trend Micro (US)
February 6, 2026 - Since OpenClaw can plan and reason across unfamiliar domains (C1), it is vulnerable to prompt injection and other subtle manipulation techniques that can influence agent behavior.
🌐
Antiy
antiy.net › p › clawhavoc-analysis-of-large-scale-poisoning-campaign-targeting-the-openclaw-skill-market-for-ai-agents
ClawHavoc: Analysis of Large-Scale Poisoning Campaign Targeting the OpenClaw Skill Market for AI Agents - Antiy Labs | The Next Generation Anti-Virus Engine Innovator
February 3, 2026 - This vulnerability was exploited by attackers as an ideal vector for malware distribution, enabling a classic supply chain attack (MITRE ATT&CK T1195): attackers poisoned upstream skill repositories, leveraging user trust in the platform to inject malicious logic into downstream endpoints.
🌐
Conscia
conscia.com › blog › the openclaw security crisis
The OpenClaw security crisis | Conscia
February 23, 2026 - Within three weeks of its surge in popularity, OpenClaw became the focal point of a multi-vector security crisis involving a critical remote code execution vulnerability (CVE-2026-25253), a large-scale supply-chain poisoning campaign in its ...
🌐
Repello
repello.ai › home › blog › malicious openclaw skills exposed: a full teardown
Malicious OpenClaw Skills Exposed: A Full Teardown | Repello AI
February 16, 2026 - CVE-2026-25253, a One-Click Remote Code Execution vulnerability with a CVSS score of 8.8, demonstrated that the OpenClaw Control UI trusted a gatewayUrl parameter from the query string without validation, enabling token exfiltration with a single ...
🌐
Kaspersky
kaspersky.com › blog › openclaw-vulnerabilities-exposed › 55263
New OpenClaw AI agent found unsafe for use | Kaspersky official blog
February 10, 2026 - A security audit conducted in late January 2026 — back when OpenClaw was still known as Clawdbot — identified a full 512 vulnerabilities, eight of which were classified as critical.
🌐
HKCERT
hkcert.org › blog › openclaw-s-rapid-adoption-exposes-skills-supply-chain-and-fake-installer-risks-in-a-high-privilege-ai-agent-platform
OpenClaw’s Rapid Adoption Exposes Skills Supply Chain and Fake Installer Risks in a High-Privilege AI Agent Platform
March 17, 2026 - Research has shown that OpenClaw previously contained a vulnerability chain that could be exploited by malicious websites, allowing attackers to silently take over a developer’s AI agent without requiring plugins, browser extensions, or user interaction.