Is a ClawHub skill safe to install?
Why the answer is "not automatically"
A ClawHub skill is a folder with a SKILL.md file that your OpenClaw agent reads as instructions. Whatever the agent can reach, such as your shell, files, email or keys, the skill's instructions can ask it to use. Installing a skill is closer to running someone else's script than to installing a browser theme.
The marketplace has been a real target. Koi Security audited the 2,857 skills on ClawHub in early February 2026 and reported 341 as malicious. Snyk scanned 3,984 skills from ClawHub and skills.sh and confirmed 76 malicious payloads by hand. Most skills are not malicious, but the share that is matters when one bad install can expose every credential your agent holds.
What ClawHub already does
Since February 2026 every skill published to ClawHub is scanned with VirusTotal, including its Code Insight review, and the result is shown on the skill page. Skills judged malicious are blocked from download. OpenClaw's maintainers call this "not a silver bullet", and public reports describe skills that passed because their payload lived on an outside website. A clean marketplace result is one useful signal, not proof of safety.
What to check before you install
- The listing. Find the skill on ClawHub or its publisher's repository, not through a shared link, and check the name letter by letter for lookalikes.
- The setup section. A "prerequisite" that downloads and runs a script, binary or archive is the most common malicious pattern in public reports. Stop there.
- Every link and command. Encoded commands, paste sites, raw IP addresses and password-protected archives are reasons to stop.
- What it can reach. Credential files, wallets, or network hosts that do not fit the skill's job need a clear reason.
- A scan. Run
npx ironheights scan ./path/to/skillor paste the file into the browser scanner. Read every finding.
The 10-minute checklist walks through this in order, and the checklist tool records your answers.
Limits of any check
No checklist or scanner can prove a skill is safe. Ironheights matches known patterns in files; it cannot see a payload on a linked website, behavior that appears only at runtime, or instructions that use no pattern its rules describe. See what Ironheights does not detect and the limitations page. Reduce the damage a missed skill can do by running new skills in an agent without production keys or funded wallets.
Sources
- OpenClaw Partners with VirusTotal for Skill Security, OpenClaw, 7 February 2026.
- ClawHavoc: 341 Malicious Clawed Skills Found by the Bot They Were Targeting, Koi Security (archived copy).
- Snyk ToxicSkills study, Snyk, 5 February 2026.
- Malicious ClawHub Skills Use External Websites to Hide in Plain Sight, OpenSourceMalware.