alert
Apr 10, 2026
By Teun
12% of ClawHub Skills Found to Contain Malicious Code
Security firm Reco found that 341 out of roughly 13,700 community-built skills on ClawHub contained malicious payloads — including prompt injections, hidden malware, and unsafe data handling patterns.
Security firm Reco says 341 of roughly 13,700 community-built ClawHub skills contained malicious code, which works out to about 12% of the registry. According to the company’s findings, the payloads included prompt injections, hidden malware, and unsafe data handling patterns that could expose SSH keys or API credentials.
That matters because ClawHub skills are not just ordinary scripts. They run inside AI agents that may already have access to files, shells, and secrets, so a bad skill can do more than crash a workflow, it can steer the agent’s behavior or quietly pull sensitive data out of the environment.
⚡ New to this?
Reco, a security firm, found that a notable share of community-made ClawHub skills contained malicious code. A skill is a small add-on that gives an AI agent extra abilities, and malicious code can mean hidden instructions, malware, or code that steals secrets.
This matters because AI agents often have access to files, terminals, and API keys. If a bad skill is installed, it can change what the agent does or expose sensitive data without being obvious right away.
🦞 OpenClaw angle
Treat third-party skills like untrusted software, not helper snippets. Before installing, check whether the requested permissions actually match the skill’s job, and reject anything that asks for shell access, file access, or secrets without a clear reason.
Use registry scans as a first filter, but do not stop there. For any skill that will touch production systems or credentials, read the source and inspect the prompt text or instructions for hidden behavior before you let an agent run it.
The report also suggests this is not a theoretical problem. Some of the flagged skills had been live for weeks before they were identified, which shows how long malicious code can sit in an open ecosystem before anyone notices.
The attack styles here are worth separating. Prompt injection is when a skill contains instructions meant to override or manipulate the agent’s behavior, while hidden malware and unsafe data handling are more familiar security issues, the kind that can lead to credential theft or unauthorized access.
OpenClaw now partners with VirusTotal to scan skills, and users can check a report on any skill’s ClawHub page before installing. According to the existing guidance, automated scanning helps catch obvious malware, but it will not reliably spot prompt injections buried in a skill’s system prompt or other logic.
That leaves manual review as the real control for higher-risk installs. A skill that asks for permissions that do not match its stated purpose, such as a weather tool requesting shell access, is a red flag and should be treated as suspect before it is allowed into an agent environment.
The broader lesson is that AI automation platforms are starting to inherit the same supply-chain risk that hit package managers years ago, but with a higher blast radius. On ClawHub, the next practical step is clear, scan the skill, read the code, and verify every permission before installation.