Last checked
Ironheights vs VirusTotal
Short answer: they sit at different points in the chain, so most people should rely on both. VirusTotal checks every skill when it is published to ClawHub. Ironheights checks the copy on your machine, before and after you install it.
At a glance
| VirusTotal on ClawHub | Ironheights | |
|---|---|---|
| Where it runs | A cloud service. ClawHub sends every published skill to it and re-scans active skills daily[1] | On your machine, as a command-line tool you run before and after installing a skill (how it works) |
| What it looks at | A ZIP bundle of the skill, read by Code Insight (an LLM review powered by Gemini) starting from SKILL.md, plus more than 70 antivirus scanners[1][3] | Skill files as text, matched against 35 published rules. It never runs a file and does not extract archives (rules) |
| Reads intent | Yes. Code Insight summarizes what the skill actually does, for example a mandatory download-and-run “prerequisite”[2] | No. Fixed patterns decide the verdict (an optional local-model note is advisory only), and they miss plain-language manipulation that matches no rule (limitations) |
| Known malware files | Strong: antivirus engines and a large shared corpus can name malware families in bundled binaries[3] | Flags bundled binaries and archives as a finding, but cannot tell you which malware family they are |
| Changes after install | Re-scans the published version on ClawHub[1] | Signed baselines for your installed skills and agent files (AGENTS.md, SOUL.md, openclaw.json, .env) report what changed. An optional guard plugin logs risky tool calls and is not a sandbox |
| Where your files go | Uploads are shared with VirusTotal's partners and community, and contents may be shared with premium customers[3] | Nowhere. Scans make no network call and there is no telemetry. Only commands you choose, such as fetch, use the network (privacy) |
| Cost and effort | Automatic for anyone installing from ClawHub. The public API is free for non-commercial use, limited to 4 requests a minute and 500 a day[4] | Free and open source (Apache-2.0). You install and run it yourself with Node.js 20 or newer |
| Published accuracy on skills | VirusTotal reported analyzing more than 3,016 OpenClaw skills, with hundreds showing malicious characteristics. We found no published recall or false-positive rate[2] | Only a synthetic 20-skill regression check so far, not a real-world rate[5] |
Where each one is stronger
What neither one catches well
OpenClaw's own announcement says VirusTotal scanning “is not a silver bullet” and that a skill using natural language to instruct an agent, or a carefully crafted prompt injection, may not be caught[1]. The same applies to Ironheights: a pattern scanner cannot judge intent, and neither tool watches what an agent does at runtime.
How to use both
- On ClawHub, read the VirusTotal status on the skill page. A warning is a reason to stop.
- Before installing, scan the skill folder on your machine and read every finding.
- After installing, record a baseline, and run verify after updates.
- For anything with access to credentials or money, also work through the skill safety checklist.
Head-to-head numbers
On our 20-skill synthetic corpus, no VirusTotal engine flagged any sample and no Code Insight verdict came back. That is expected: the samples are one-line instruction files we wrote to match our own rules, and VirusTotal's engines are built for binaries and file reputation. It says little about how VirusTotal does on real ClawHub malware, and we make no claim that Ironheights beats it there. Details are on the benchmark page.
Sources
- OpenClaw Partners with VirusTotal for Skill Security, OpenClaw blog, 7 February 2026.
- From Automation to Infection: How OpenClaw AI Agent Skills Are Being Weaponized, VirusTotal blog, 2 February 2026.
- How it works, VirusTotal documentation.
- Public vs Premium API, VirusTotal documentation.
- Ironheights benchmark #1, Ironheights, 9 October 2026.
All sources last checked on 9 October 2026.