Skill safetyUpdated

What is OpenClaw skill supply-chain risk?

Short answer

OpenClaw skill supply-chain risk is the risk you take on by running instructions written by someone else. A third-party skill, a later update to it, or a website or file it depends on can turn harmful, and it acts with your agent's access to files, accounts and keys. It is the agent version of a malicious package.

Why skills are a supply chain

Every skill you install is a dependency. You trust its author, the marketplace that hosted it, every update after your review, and anything it fetches while it runs. That is the same chain of trust as a software package, with two differences that make it sharper.

First, the artifact is language. A skill can be harmful without containing code, because the agent follows its instructions. Second, the privilege is high. A skill inherits whatever the agent can do, which often includes a shell, email, source code, cloud accounts or a wallet.

Where the risk enters

  • At publish time. A malicious author publishes a lookalike or a useful-sounding skill. Public reports counted hundreds in early 2026.
  • Through dependencies. The skill tells you to install a "required" tool from a website or archive. The tool is the payload.
  • After review. The skill updates, or a file in your workspace changes, and the version you vetted is no longer the version you run.
  • At runtime. The skill fetches instructions or data from a server on every use, so its behavior can change without any file changing. Unit 42 described a skill that rotated affiliate links this way.
  • Through popularity. Download counts are not a safety signal; JFrog reported over 5,000 downloads in 19 days for one padded dropper.

Who is most exposed

Small teams and agencies that let agents touch email, source code, customer data, cloud accounts or crypto carry the most risk, because one bad skill reaches all of it. A solo user with a sandboxed agent and no real credentials carries far less. The first question to ask is not "is this skill safe?" but "what could it reach if it were not?"

How to reduce it

Treat it the way mature teams treat package risk:

  1. Vet before install. Use a checklist and a scanner such as the browser scanner or npx ironheights scan.
  2. Pin and re-vet. Re-check a skill on every update instead of trusting the publisher forever.
  3. Detect drift. Record a baseline and run ironheights verify to see added, modified or removed files. See how to check if a skill changed.
  4. Limit access. Run new skills in an agent without production credentials.
  5. Watch the reports. Our malicious skill tracker collects public cases with sources.

Limits

A file scanner covers the first and third points only partly. It cannot see payloads on linked websites or behavior that changes at runtime. See the limitations page.

Sources

  • A malicious ClawHub skill is an OpenClaw skill written to make your agent or you run malware, leak credentials or move money. Patterns from 2026 reports.
  • Record a baseline of OpenClaw skills and agent files with ironheights baseline create, then run ironheights verify to list added, modified and removed files.
  • Not by default. ClawHub scans skills, but malicious ones have passed. How to check a skill's listing, setup, links and access before your OpenClaw agent reads it.

All answers

Check the next skill before your agent reads it

Ironheights is a free, open-source, local-first scanner and integrity monitor for OpenClaw skills. It reports what its rules match; it cannot prove a skill is safe.