Case · DiggingBeagle record
Malicious OpenClaw skills abused the agent's inherited local authority
This record is an ecosystem-level study of malicious OpenClaw/ClawHub skills rather than one incident. Snyk scanned 3,984 skills and found 1,467 with at least one security issue, but its intentionally malicious subset was a separate 76 human-confirmed payloads; those populations must not be conflated. Unit 42 later identified five malicious skills that remained unblocked during February-May, spanning infostealers, scanner evasion and agent-specific financial manipulation. The common mechanism is inherited agent authority: natural-language skill instructions can cause an agent to use filesystem, shell, credential-manager or authenticated-session capabilities without a conventional software exploit. Marketplace scanning and takedowns removed known artifacts, but observed scanner-evasion techniques show that a clean or accepted scan is not equivalent to a safe skill, and public evidence still does not establish a reliable victim population.
Assessment profile
Assessment method- Setting
- production
- Exploitation
- observed live
- Evidence
- Grade B
- Remediation
- mitigation available
Basis and provenance
Two security-research studies establish malicious skills in the public ecosystem and document concrete malicious mechanisms plus takedowns. Study populations and scanner methodologies differ, and no reliable victim-compromise denominator is established, so impact is left unbanded.
Assessed Oct 5, 2026 using diggingbeagle.assessment/1.
Evidence basis: CLM-OPENCLAW-TOXICSKILLS-SPLIT · CLM-OPENCLAW-UNIT42-FIVE · CLM-OPENCLAW-SCANNER-EVASION · CLM-OPENCLAW-POPULATION-BOUNDARY · ToxicSkills: malicious AI Agent Skills and supply-chain compromise · OpenClaw's Skill Marketplace and the emerging AI supply-chain threat
Timeline
- 2026-02 (month precision) to 2026-05 (month precision)Event type unspecified
Unit 42 observed five additional malicious skill patterns
Across the February-May study window, Unit 42 documented infostealers, scanner evasion and agent-specific financial manipulation that remained unblocked long enough to investigate.
- 2026-02 (month precision)disclosure
Public disclosure
- Feb 5, 2026disclosure
Snyk published ToxicSkills ecosystem scan
The study separated broad security findings across 3,984 skills from a human-confirmed subset of 76 intentionally malicious payloads.
- 2026-05 (month precision)Event type unspecified
Reported Unit 42 skills were removed
Unit 42 says all five newly identified malicious skills were reported and removed and the associated accounts were banned; the study also documents continuing marketplace screening improvements.
Claims & evidence
CLM-OPENCLAW-UNIT42-FIVEUnit 42 reported five malicious ClawHub skills that remained unblocked during its February-May analysis: two infostealer skills, one scanner-evasion skill and two agentic financial-threat skills; Unit 42 says it reported all five and the accounts and skills were subsequently removed.supported
Basis: reported finding
- supportsOpenClaw's Skill Marketplace and the emerging AI supply-chain threatprimary disclosure
Executive Summary, lines describing five unblocked skills and the three threat categories
CLM-OPENCLAW-SCANNER-EVASIONUnit 42 documented a malicious skill using large-file padding to evade or exceed scanner handling, including an `omnicogg` artifact that appeared clean or under review in marketplace scanners while remaining available, showing that marketplace scanning did not eliminate malicious-skill availability during the study window.supported
Basis: reported finding
- supportsOpenClaw's Skill Marketplace and the emerging AI supply-chain threatprimary disclosure
File Padding for Defense Evasion; scanner-status discussion and associated figure
CLM-OPENCLAW-TOXICSKILLS-SPLITSnyk scanned 3,984 skills and found 534 with at least one critical-level issue and 1,467 with at least one issue of any severity; separately, human-in-the-loop review confirmed 76 intentionally malicious payloads designed for credential theft, backdoor installation or data exfiltration. Snyk's corpus deduplication was keyed by author and skill identity rather than proving that differently republished skill IDs were independent malware families.supported
Basis: reported finding
- supportsToxicSkills: malicious AI Agent Skills and supply-chain compromiseprimary disclosure
Opening study results; findings table; dataset/deduplication discussion; 'Beyond the statistics' HITL-confirmed malicious-payload paragraph
CLM-OPENCLAW-INHERITED-AUTHORITYUnit 42 describes OpenClaw skills as markdown-driven packages with broad local access and documents malicious instructions that leverage the agent's own filesystem, shell, credential-manager or authenticated-session authority rather than requiring a conventional software exploit.supported
Basis: reported finding
- supportsOpenClaw's Skill Marketplace and the emerging AI supply-chain threatprimary disclosure
AI Agent Skills as a Supply Chain Attack Surface
- contextToxicSkills: malicious AI Agent Skills and supply-chain compromiseprimary disclosure
What makes Agent Skills dangerous
CLM-OPENCLAW-POPULATION-BOUNDARYThe Snyk security-issue prevalence, the human-confirmed malicious subset, Unit 42's five later unblocked skills and any marketplace download or listing counts describe different populations; none of those figures is a verified victim-compromise count.supported
Basis: inference
- supportsToxicSkills: malicious AI Agent Skills and supply-chain compromiseprimary disclosure
Study population, findings table and HITL-confirmed malicious subset
- supportsOpenClaw's Skill Marketplace and the emerging AI supply-chain threatprimary disclosure
Executive Summary and five-skill study population
CLM-OPENCLAW-MARKETPLACE-RESPONSEUnit 42 reports that earlier malicious-skill findings prompted ClawHub to add VirusTotal and ClawScan screening, that the five skills identified in its later study were reported and removed with associated accounts banned, and that further screening partnerships were announced. These controls removed known artifacts but did not prevent all malicious or evasive skills from appearing during the study period.supported
Basis: reported finding
- supportsOpenClaw's Skill Marketplace and the emerging AI supply-chain threatprimary disclosure
Executive Summary; marketplace security response; VirusTotal/ClawScan discussion; takedown and later screening-partnership discussion
Sources and citation
Material revision history
- Oct 5, 2026 · Published version · first publication · revision 68
Cite this record
DiggingBeagle. “Malicious OpenClaw skills abused the agent's inherited local authority.” Published by DiggingBeagle Oct 5, 2026 · Public disclosure 2026-02 (month precision). https://diggingbeagle.com/cases/malicious-openclaw-skills-abused-the-agent-s-inherited-local-authority/