Last checked

Ironheights vs VirusTotal

Short answer: they sit at different points in the chain, so most people should rely on both. VirusTotal checks every skill when it is published to ClawHub. Ironheights checks the copy on your machine, before and after you install it.

At a glance

VirusTotal on ClawHub compared with Ironheights
VirusTotal on ClawHubIronheights
Where it runsA cloud service. ClawHub sends every published skill to it and re-scans active skills daily[1]On your machine, as a command-line tool you run before and after installing a skill (how it works)
What it looks atA ZIP bundle of the skill, read by Code Insight (an LLM review powered by Gemini) starting from SKILL.md, plus more than 70 antivirus scanners[1][3]Skill files as text, matched against 35 published rules. It never runs a file and does not extract archives (rules)
Reads intentYes. Code Insight summarizes what the skill actually does, for example a mandatory download-and-run “prerequisite”[2]No. Fixed patterns decide the verdict (an optional local-model note is advisory only), and they miss plain-language manipulation that matches no rule (limitations)
Known malware filesStrong: antivirus engines and a large shared corpus can name malware families in bundled binaries[3]Flags bundled binaries and archives as a finding, but cannot tell you which malware family they are
Changes after installRe-scans the published version on ClawHub[1]Signed baselines for your installed skills and agent files (AGENTS.md, SOUL.md, openclaw.json, .env) report what changed. An optional guard plugin logs risky tool calls and is not a sandbox
Where your files goUploads are shared with VirusTotal's partners and community, and contents may be shared with premium customers[3]Nowhere. Scans make no network call and there is no telemetry. Only commands you choose, such as fetch, use the network (privacy)
Cost and effortAutomatic for anyone installing from ClawHub. The public API is free for non-commercial use, limited to 4 requests a minute and 500 a day[4]Free and open source (Apache-2.0). You install and run it yourself with Node.js 20 or newer
Published accuracy on skillsVirusTotal reported analyzing more than 3,016 OpenClaw skills, with hundreds showing malicious characteristics. We found no published recall or false-positive rate[2]Only a synthetic 20-skill regression check so far, not a real-world rate[5]

Where each one is stronger

Where VirusTotal is stronger
  • It is already on: every ClawHub skill is checked at publish time with no setup, and malicious verdicts block the download[1].
  • An LLM reads the skill for intent, so it can catch a harmful workflow even when no single line looks like malware[2].
  • More than 70 antivirus engines and a large threat-intelligence corpus are far better than a text scanner at identifying real malware binaries[3].
  • Its findings on OpenClaw campaigns, such as 314 malicious skills from a single publisher, come from real marketplace data[2].
Where Ironheights is different
  • It checks the copy you actually have, including skills from outside ClawHub, a local folder, or a repository.
  • Baseline and verify tell you when an installed skill or an agent file changes after you approved it.
  • Nothing leaves your machine, which matters for private or client skills you cannot upload to a shared service.
  • Every rule is published and every finding points at a file and line, so you can see why it fired.

What neither one catches well

How to use both

  1. On ClawHub, read the VirusTotal status on the skill page. A warning is a reason to stop.
  2. Before installing, scan the skill folder on your machine and read every finding.
  3. After installing, record a baseline, and run verify after updates.
  4. For anything with access to credentials or money, also work through the skill safety checklist.
npx ironheights scan ./path/to/skill
npx ironheights baseline create
npx ironheights verify

Head-to-head numbers

On our 20-skill synthetic corpus, no VirusTotal engine flagged any sample and no Code Insight verdict came back. That is expected: the samples are one-line instruction files we wrote to match our own rules, and VirusTotal's engines are built for binaries and file reputation. It says little about how VirusTotal does on real ClawHub malware, and we make no claim that Ironheights beats it there. Details are on the benchmark page.

Sources

  1. OpenClaw Partners with VirusTotal for Skill Security, OpenClaw blog, 7 February 2026.
  2. From Automation to Infection: How OpenClaw AI Agent Skills Are Being Weaponized, VirusTotal blog, 2 February 2026.
  3. How it works, VirusTotal documentation.
  4. Public vs Premium API, VirusTotal documentation.
  5. Ironheights benchmark #1, Ironheights, 9 October 2026.

All sources last checked on 9 October 2026.