clawsmith.com/signal/clawhub-ranking-manipulation-unauthenticated-download-inflate
⚠ IssueUnderservedSecurityLive
ClawHub Ranking Manipulation: Unauthenticated RPC Inflates Download Counter to Push Malicious Skill to #1
Silverfort discovers ClawHub's download.increment mutation is an unauthenticated public RPC endpoint with no rate limiting or validation. PoC skill reaches #1 position in category with 3,900 executions across 50+ cities in 6 days, infiltrating several public companies. Payload exfiltrated usernames and domain names. Fix deployed within 24 hours of March 16 2026 disclosure.
Product Idea from this Signal
A background service that continuously audits ClawHub skill download counts, detects ranking inflation, and flags skills with suspicious promotion patterns before users install them
154 ▲SECURITYOPEN-SOURCECLIREGISTRY-INTEGRITYSUPPLY-CHAIN
CompetitiveView Opportunity →
Score Breakdown
HN
91
Issues
63
Social Proof 2 sources
Gap Assessment
UnderservedExisting solutions leave gaps
Patched by OpenClaw team within 24h but exposed fundamental trust architecture weakness in ClawHub skill registry
Frequently Asked Questions
Virality Score
154
across 2 platforms
Details
Signalissue
EcosystemSecurity
Sources2
Platforms2
Updated19d ago
Trend→ stable
Top ideas
All ideas →Related signals
All signals →