AI Skills Marketplace Becomes a Credential Channel
The danger is not five bad add-ons. It is that a third-party skill in an AI marketplace can inherit the agent’s own trust and reach the same files, secrets, and connected services the user can reach. That makes package review alone too narrow, because the risk shows up after install, at runtime.
Unit42 found five malicious OpenClaw skills on ClawHub. They covered infostealing, scan evasion, and agentic abuse, and OpenClaw removed them after review. The skills could access local files, credentials, APIs, and workflows, which means a seemingly legitimate marketplace package can steal data, hide from scanners, and trigger unauthorized actions through trusted integrations.
The pattern matters beyond OpenClaw. Any AI assistant that can load third-party tools and touch local data or SaaS connectors inherits the same trust problem, and that risk persists even if the package itself looks clean.