clawsmith.com/signal/clawhavoc-1184-malicious-clawhub-skills
⚠ IssueCompetitiveClawHub SkillLive
ClawHavoc Campaign: 824+ Malicious ClawHub Skills, 12% of Marketplace Is Malware
Of 2,857 initial skills, 341 confirmed malicious (12%). Marketplace grew to 10,700+ skills, malicious count rose to 824 with 25 new attack types. Includes keyloggers, credential stealers, prompt injection payloads, crypto stealers.
Product Idea from this Signal
A security layer that vets ClawHub skills for malware and prompt injection before your agent installs them
133.9k ▲SECURITYCLIDEVTOOLOPEN-SOURCE
CompetitiveView Opportunity →
Product Idea from this Signal
A pre-install verification gate that formally proves an AI agent skill cannot exceed its declared capabilities before allowing it onto your system
13.0k ▲CLIOPEN-SOURCESECURITYDEVTOOLFORMAL-VERIFICATION
CompetitiveView Opportunity →
Product Idea from this Signal
A runtime behavioral sandbox that detects guidance injection attacks in OpenClaw skills by observing what agents actually do instead of scanning what skills say
17.6k ▲CLIOPEN-SOURCESECURITYDEVTOOLRUNTIME-ANALYSIS
CompetitiveView Opportunity →
Score Breakdown
HN
2,880
BLOG
2,720
Reddit
2,340
Social Proof 6 sources
RD2,340BL1,800HN1,180BL920HN910HN790
20% of ClawHub skills are malicious — ClawHavoc
2/10/2026
From Automation to Infection: How OpenClaw Skills Are Being Weaponized (VirusTotal)
2/15/2026
ClawHavoc: Malicious Clawed Skills | HN
2/8/2026
OpenClaw Skill Marketplace Emerges as Active Malware Vector (Socket.dev)
3/10/2026
Malicious Skills in ClawHub Marketplace | HN
2/9/2026
Top downloaded ClawHub skill contains malware | HN
2/8/2026
Existing Solutions 5 competitors
VirusTotal IntegrationIntegrated natively into ClawHub; live for all 10,700+ skills.
Google's VirusTotal now scans all skills published to ClawHub for malware.
Cisco Skill ScannerOpen source, Cisco-backed.
Open-source CLI skill scanner released by Cisco for community skill vetting.
SecureClawOpen source, maps to OWASP Agentic Security Initiative top 10.
55-check automated audit and hardening tool for OpenClaw skill supply chain.
openclaw-security-monitorGitHub, growing community adoption.
Proactive monitoring detecting ClawHavoc, AMOS stealer, CVE-2026-25253, and memory poisoning.
Clawned.ioCommunity scanner, HN frontpage.
Crowdsource public security scanner for OpenClaw skills.
Gap Assessment
CompetitiveMarket has established players
VirusTotal live in ClawHub; 5+ dedicated scanners (SecureClaw, clawvet, Cisco, openclaw-security-monitor, Clawned.io) already deployed.
Frequently Asked Questions
Virality Score
7,940
across 3 platforms
Details
Signalissue
EcosystemClawHub Skill
Sources6
Platforms3
Updated1d ago
Trend→ stable
Top ideas
All ideas →Related signals
All signals →