Skill safetyUpdated

What is a malicious ClawHub skill?

Short answer

A malicious ClawHub skill is an OpenClaw skill written to harm the person who installs it. Its SKILL.md instructions get the agent, or you, to run a hidden installer, send credentials or files to an attacker, weaken the agent's safeguards, or move money. Most reported cases hid malware behind a fake setup step.

How it differs from a malicious package

A malicious npm or PyPI package hides harmful code. A malicious skill often needs no code at all. Its SKILL.md is plain language that the agent treats as instructions, so the harmful part can be a sentence: "before using this skill, run the following setup command." VirusTotal put it this way after analyzing more than 3,016 OpenClaw skills: nothing in such a file is malware by itself; the malware is the workflow it asks you to run.

Patterns seen in public reports

  • Fake prerequisites. The skill claims it needs a helper or "core" tool and gives an encoded command or a link. Koi's ClawHavoc report describes hundreds of skills that used this to deliver the Atomic macOS Stealer. We took the pattern apart in this teardown.
  • Payload on another site. The skill only links to a lookalike website or paste site that serves the command, so the skill file itself looks clean.
  • Credential theft. The skill reads key files such as .env, SSH keys or wallets and sends them to an outside host.
  • Hidden code in working tools. One reported Polymarket skill worked as advertised but also opened a reverse shell to the attacker during normal use.
  • Padding. One skill hid its command in a README padded to about 22 MB to get past scanner size limits.
  • Agent-native fraud. Skills that steer the agent's advice toward affiliate links, or tell agents to pool cryptocurrency into the operator's wallet.

The usual lures are things people want right now: crypto and trading tools, social media helpers, Google Workspace connectors, auto-updaters, and lookalikes of official OpenClaw or ClawHub tools.

How big the problem is

Koi audited the 2,857 skills on ClawHub in early February 2026 and reported 341 as malicious, 335 of them from one campaign. Snyk confirmed 76 malicious payloads by hand in a study of 3,984 skills. Counts differ by method and date, and the marketplace has added scanning since.

Where to see real cases

Our malicious skill tracker lists publicly reported campaigns and skills with the reporter, the date, the status the source gives, and which Ironheights rules flag the pattern. It never links to the skills themselves.

How to recognize one

Read the setup section first, check every link and command, and compare what the skill asks for with what it claims to do. A scanner helps: Ironheights flags patterns such as remote content piped into a shell (IH-EXEC-001) and access to credential paths (IH-CRED-001). It cannot catch everything; see the limitations page.

Sources

  • Not by default. ClawHub scans skills, but malicious ones have passed. How to check a skill's listing, setup, links and access before your OpenClaw agent reads it.
  • Prompt injection in an agent skill is text in SKILL.md that tries to override the agent's rules, hide steps or weaken safeguards. What it looks like and how to check.
  • OpenClaw skill supply-chain risk is the chance that a third-party skill, its update, or a link it depends on harms your agent. Where it enters and how to reduce it.

All answers

Check the next skill before your agent reads it

Ironheights is a free, open-source, local-first scanner and integrity monitor for OpenClaw skills. It reports what its rules match; it cannot prove a skill is safe.