Evidence · DiggingBeagle record
OpenClaw's Skill Marketplace and the emerging AI supply-chain threat
Unit 42 analysis of OpenClaw/ClawHub malicious skills from February-May 2026, including infostealer delivery, scanner evasion and agent-specific financial manipulation; the five newly identified skills were reported and removed.
- Source role
- primary disclosure
Evidence record
Unit 42 analysis of OpenClaw/ClawHub malicious skills from February-May 2026, including infostealer delivery, scanner evasion and agent-specific financial manipulation; the five newly identified skills were reported and removed.
Claim-level citations (5)
- supportsMalicious OpenClaw skills abused the agent's inherited local authority: Unit 42 reported five malicious ClawHub skills that remained unblocked during its February-May analysis: two infostealer skills, one scanner-evasion skill and two agentic financial-threat skills; Unit 42 says it reported all five and the accounts and skills were subsequently removed.
Executive Summary, lines describing five unblocked skills and the three threat categories
- supportsMalicious OpenClaw skills abused the agent's inherited local authority: Unit 42 documented a malicious skill using large-file padding to evade or exceed scanner handling, including an `omnicogg` artifact that appeared clean or under review in marketplace scanners while remaining available, showing that marketplace scanning did not eliminate malicious-skill availability during the study window.
File Padding for Defense Evasion; scanner-status discussion and associated figure
- supportsMalicious OpenClaw skills abused the agent's inherited local authority: Unit 42 describes OpenClaw skills as markdown-driven packages with broad local access and documents malicious instructions that leverage the agent's own filesystem, shell, credential-manager or authenticated-session authority rather than requiring a conventional software exploit.
AI Agent Skills as a Supply Chain Attack Surface
- supportsMalicious OpenClaw skills abused the agent's inherited local authority: The Snyk security-issue prevalence, the human-confirmed malicious subset, Unit 42's five later unblocked skills and any marketplace download or listing counts describe different populations; none of those figures is a verified victim-compromise count.
Executive Summary and five-skill study population
- supportsMalicious OpenClaw skills abused the agent's inherited local authority: Unit 42 reports that earlier malicious-skill findings prompted ClawHub to add VirusTotal and ClawScan screening, that the five skills identified in its later study were reported and removed with associated accounts banned, and that further screening partnerships were announced. These controls removed known artifacts but did not prevent all malicious or evasive skills from appearing during the study period.
Executive Summary; marketplace security response; VirusTotal/ClawScan discussion; takedown and later screening-partnership discussion
Cite this record
DiggingBeagle. “OpenClaw's Skill Marketplace and the emerging AI supply-chain threat.” https://diggingbeagle.com/sources/openclaw-s-skill-marketplace-and-the-emerging-ai-supply-chain-threat/