Skill safetyUpdated

Does VirusTotal scan ClawHub skills?

Short answer

Yes. Since 7 February 2026, every skill published to ClawHub is scanned with VirusTotal, including Code Insight, an LLM review of SKILL.md and the files it references. Benign skills are approved, suspicious ones get a warning, malicious ones are blocked from download, and active skills are re-scanned daily. OpenClaw calls it helpful but not a silver bullet.

How the integration works

OpenClaw announced the partnership on its blog in February 2026. Each published skill is checked by VirusTotal's antivirus engines and by Code Insight, which reads the skill's instructions and referenced files with a language model. The verdict decides what happens on ClawHub: approval, a visible warning, or a block on downloads. Skills stay under watch with daily re-scans.

VirusTotal's own research is the reason this matters. In early February it reported analyzing more than 3,016 OpenClaw skills, with hundreds showing malicious characteristics, 314 of them tied to a single user.

What it has missed

OpenClaw's maintainers say well-concealed prompt injection can get through. Public reports show other gaps:

  • OpenSourceMalware reported about 40 skills whose files contained no malicious code, only a link to a lookalike website that served the command. Because the skill files were clean, VirusTotal scanning of the skills did not catch them.
  • Unit 42 reported that ClawHub's automated audit returned Pass or no verdict for two skills published in May 2026 that sent the agent to a paste site hosting an infostealer command.

These are not failures unique to VirusTotal. Any scanner that reads only the skill file has the same blind spot when the payload lives elsewhere.

What our own test showed, and did not

We uploaded the 20 skills of our synthetic benchmark corpus to public VirusTotal. No engine flagged any of them, and no Code Insight result appeared. That says very little about VirusTotal: the samples are one-line Markdown files written to match our rules, its engines are built for binaries and file reputation, and we did not measure the Code Insight verdict ClawHub actually uses. Details are on the benchmark page and in our VirusTotal comparison.

Marketplace scan versus local scan

The two checks sit at different points. ClawHub's VirusTotal scan runs once at publish time and again daily on the listing. A local scanner checks the copy that is actually on your machine, before you install it and after, and can compare it with a saved baseline to show what changed. Neither replaces reading the skill.

What to add on your side

Read the marketplace verdict first; a warning means stop. Then do what the marketplace cannot: check the copy on your machine with a scanner such as Ironheights (npx ironheights scan ./path/to/skill), and record a baseline so you notice if it changes later. Ironheights has its own limits.

Sources

  • Not by default. ClawHub scans skills, but malicious ones have passed. How to check a skill's listing, setup, links and access before your OpenClaw agent reads it.
  • Verify a ClawHub skill in five steps: confirm the listing and publisher, read the scan status, read SKILL.md's setup and links, scan it, and record a baseline.
  • Ironheights misses payloads on linked sites, files over 1 MiB by default, runtime behavior, money-moving instructions and novel attacks. What to do about each.

All answers

Check the next skill before your agent reads it

Ironheights is a free, open-source, local-first scanner and integrity monitor for OpenClaw skills. It reports what its rules match; it cannot prove a skill is safe.