Case · DiggingBeagle record

Malicious OpenClaw skills abused the agent's inherited local authority

This record is an ecosystem-level study of malicious OpenClaw/ClawHub skills rather than one incident. Snyk scanned 3,984 skills and found 1,467 with at least one security issue, but its intentionally malicious subset was a separate 76 human-confirmed payloads; those populations must not be conflated. Unit 42 later identified five malicious skills that remained unblocked during February-May, spanning infostealers, scanner evasion and agent-specific financial manipulation. The common mechanism is inherited agent authority: natural-language skill instructions can cause an agent to use filesystem, shell, credential-manager or authenticated-session capabilities without a conventional software exploit. Marketplace scanning and takedowns removed known artifacts, but observed scanner-evasion techniques show that a clean or accepted scan is not equivalent to a safe skill, and public evidence still does not establish a reliable victim population.

Assessment profile

Assessment method
Setting
production
Exploitation
observed live
Evidence
Grade B
Remediation
mitigation available
Basis and provenance

Two security-research studies establish malicious skills in the public ecosystem and document concrete malicious mechanisms plus takedowns. Study populations and scanner methodologies differ, and no reliable victim-compromise denominator is established, so impact is left unbanded.

Assessed Oct 5, 2026 using diggingbeagle.assessment/1.

Timeline

  1. 2026-02 (month precision) to 2026-05 (month precision)
    Event type unspecified

    Unit 42 observed five additional malicious skill patterns

    Across the February-May study window, Unit 42 documented infostealers, scanner evasion and agent-specific financial manipulation that remained unblocked long enough to investigate.

  2. 2026-02 (month precision)
    disclosure

    Public disclosure

  3. Feb 5, 2026
    disclosure

    Snyk published ToxicSkills ecosystem scan

    The study separated broad security findings across 3,984 skills from a human-confirmed subset of 76 intentionally malicious payloads.

  4. 2026-05 (month precision)
    Event type unspecified

    Reported Unit 42 skills were removed

    Unit 42 says all five newly identified malicious skills were reported and removed and the associated accounts were banned; the study also documents continuing marketplace screening improvements.

Claims & evidence

CLM-OPENCLAW-UNIT42-FIVEUnit 42 reported five malicious ClawHub skills that remained unblocked during its February-May analysis: two infostealer skills, one scanner-evasion skill and two agentic financial-threat skills; Unit 42 says it reported all five and the accounts and skills were subsequently removed.supported

Basis: reported finding

Link to claim
CLM-OPENCLAW-SCANNER-EVASIONUnit 42 documented a malicious skill using large-file padding to evade or exceed scanner handling, including an `omnicogg` artifact that appeared clean or under review in marketplace scanners while remaining available, showing that marketplace scanning did not eliminate malicious-skill availability during the study window.supported

Basis: reported finding

Link to claim
CLM-OPENCLAW-TOXICSKILLS-SPLITSnyk scanned 3,984 skills and found 534 with at least one critical-level issue and 1,467 with at least one issue of any severity; separately, human-in-the-loop review confirmed 76 intentionally malicious payloads designed for credential theft, backdoor installation or data exfiltration. Snyk's corpus deduplication was keyed by author and skill identity rather than proving that differently republished skill IDs were independent malware families.supported

Basis: reported finding

Link to claim
CLM-OPENCLAW-INHERITED-AUTHORITYUnit 42 describes OpenClaw skills as markdown-driven packages with broad local access and documents malicious instructions that leverage the agent's own filesystem, shell, credential-manager or authenticated-session authority rather than requiring a conventional software exploit.supported

Basis: reported finding

Link to claim
CLM-OPENCLAW-POPULATION-BOUNDARYThe Snyk security-issue prevalence, the human-confirmed malicious subset, Unit 42's five later unblocked skills and any marketplace download or listing counts describe different populations; none of those figures is a verified victim-compromise count.supported

Basis: inference

Link to claim
CLM-OPENCLAW-MARKETPLACE-RESPONSEUnit 42 reports that earlier malicious-skill findings prompted ClawHub to add VirusTotal and ClawScan screening, that the five skills identified in its later study were reported and removed with associated accounts banned, and that further screening partnerships were announced. These controls removed known artifacts but did not prevent all malicious or evasive skills from appearing during the study period.supported

Basis: reported finding

Link to claim

Sources and citation

Material revision history

  1. Oct 5, 2026 · Published version · first publication · revision 68

Cite this record

DiggingBeagle. “Malicious OpenClaw skills abused the agent's inherited local authority.” Published by DiggingBeagle Oct 5, 2026 · Public disclosure 2026-02 (month precision). https://diggingbeagle.com/cases/malicious-openclaw-skills-abused-the-agent-s-inherited-local-authority/

Citation guidance