What the study found
VirusTotal reported analysing more than 3,016 OpenClaw skills, hundreds of them with malicious characteristics, including 314 tied to a single user. Its point: nothing in such a skill file is malware by itself; the malware is the workflow it asks you to run.
Techniques
- Fake prerequisite
- Password-protected archive
Status, as stated by the source
A study, not a single listing.
We do not check the registry ourselves. “Unknown” means no source we found says the skill was removed.
Would Ironheights flag this pattern?
Not assessed
A measurement across many skills. We have not mapped its findings to individual rules.
Sources
- From Automation to Infection: How OpenClaw AI Agent Skills Are Being Weaponized(opens in a new tab)VirusTotal Blog · primary
Sources are the only outbound links on this page. We never link to the skills themselves or publish their payloads.
Related reports
- google-qx4 (fake openclaw-core requirement)Snyk · 10 February 2026Skill
- More skills by zaycv: linkedin-job-application, autoupdater, deepresearchCommunity reports on GitHub (adrianwedd, hendrysadrak, rafadiasbsb) · 4 February 2026Skill
- Fake “ClawHub CLI” skills by zaycv (clawhub, clawdhub1)Snyk; GitHub issue by lycfyi · 2 February 2026Skill
Related rules
No rule is mapped to this entry. Browse all rules in the rules reference, and read Limitations for what a skill scanner cannot see.