AI · 75 days ago
The danger is not five bad add-ons. It is that a third-party skill in an AI marketplace can inherit the agent’s own trust and reach the same files, secrets, and connected services the user can reach. That makes package review alone too narrow, because the risk shows up after install, at runtime.
Unit42 found five malicious OpenClaw skills on ClawHub. They covered infostealing, scan evasion, and agentic abuse, and OpenClaw removed them after review. The skills could access local files, credentials, APIs, and workflows, which means a seemingly legitimate marketplace package can steal data, hide from scanners, and trigger unauthorized actions through trusted integrations.
The pattern matters beyond OpenClaw. Any AI assistant that can load third-party tools and touch local data or SaaS connectors inherits the same trust problem, and that risk persists even if the package itself looks clean.
3 sources covering this story
Security risks for OpenClaw users and how to mitigate these risks
Researching OpenClaw vulnerabilities, malicious skills, and other security issues with the popular agent, and providing tips on how to mitigate them.
More Malicious OpenClaw Skills Threaten AI Supply Chain
OpenClaw removed five packages from ClawHub, its skills marketplace, that bypassed security even though they included infostealers and other threats.
OpenClaw’s Skill Marketplace and the Emerging AI Supply Chain Threat
Unit 42's analysis of ClawHub revealed evasive malicious skills bypassing automated scanners to deploy infostealers and execute agentic financial fraud.
Part of the PlainSec briefing for 2026-07-01