Skill safetyUpdated

Is a ClawHub skill safe to install?

Short answer

Not automatically. Most ClawHub skills are ordinary, but researchers found hundreds of malicious ones in 2026, and some passed the marketplace's VirusTotal scan. Treat every skill as code that runs with your agent's access: check the listing, read the setup section and links, scan it, and give it only the access it needs.

Why the answer is "not automatically"

A ClawHub skill is a folder with a SKILL.md file that your OpenClaw agent reads as instructions. Whatever the agent can reach, such as your shell, files, email or keys, the skill's instructions can ask it to use. Installing a skill is closer to running someone else's script than to installing a browser theme.

The marketplace has been a real target. Koi Security audited the 2,857 skills on ClawHub in early February 2026 and reported 341 as malicious. Snyk scanned 3,984 skills from ClawHub and skills.sh and confirmed 76 malicious payloads by hand. Most skills are not malicious, but the share that is matters when one bad install can expose every credential your agent holds.

What ClawHub already does

Since February 2026 every skill published to ClawHub is scanned with VirusTotal, including its Code Insight review, and the result is shown on the skill page. Skills judged malicious are blocked from download. OpenClaw's maintainers call this "not a silver bullet", and public reports describe skills that passed because their payload lived on an outside website. A clean marketplace result is one useful signal, not proof of safety.

What to check before you install

  1. The listing. Find the skill on ClawHub or its publisher's repository, not through a shared link, and check the name letter by letter for lookalikes.
  2. The setup section. A "prerequisite" that downloads and runs a script, binary or archive is the most common malicious pattern in public reports. Stop there.
  3. Every link and command. Encoded commands, paste sites, raw IP addresses and password-protected archives are reasons to stop.
  4. What it can reach. Credential files, wallets, or network hosts that do not fit the skill's job need a clear reason.
  5. A scan. Run npx ironheights scan ./path/to/skill or paste the file into the browser scanner. Read every finding.

The 10-minute checklist walks through this in order, and the checklist tool records your answers.

Limits of any check

No checklist or scanner can prove a skill is safe. Ironheights matches known patterns in files; it cannot see a payload on a linked website, behavior that appears only at runtime, or instructions that use no pattern its rules describe. See what Ironheights does not detect and the limitations page. Reduce the damage a missed skill can do by running new skills in an agent without production keys or funded wallets.

Sources

  • A malicious ClawHub skill is an OpenClaw skill written to make your agent or you run malware, leak credentials or move money. Patterns from 2026 reports.
  • Verify a ClawHub skill in five steps: confirm the listing and publisher, read the scan status, read SKILL.md's setup and links, scan it, and record a baseline.
  • Scan an OpenClaw skill before install with npx ironheights scan, or paste SKILL.md into the free browser scanner. What the verdicts mean, and what a scan misses.

All answers

Check the next skill before your agent reads it

Ironheights is a free, open-source, local-first scanner and integrity monitor for OpenClaw skills. It reports what its rules match; it cannot prove a skill is safe.