Close Menu
Daily Guardian
  • Home
  • News
  • Politics
  • Business
  • Entertainment
  • Lifestyle
  • Health
  • Sports
  • Technology
  • Climate
  • Auto
  • Travel
  • Web Stories
What's On

AI in Oil and Gas Industry Research Report 2026-2035: Market to Surpass $7.5 Billion by 2030 with IBM, Microsoft, Google, Intel Schlumberger, Halliburton, Baker Hughes Leading

March 10, 2026

Evolt Charging partners with AMPECO to support the next phase of EV Charging

March 10, 2026

Acronis Announces New #TeamUp Partnership in Switzerland with Hockey Club Davos AG and COOQIE

March 10, 2026

STMicroelectronics propels new era of ultra-wideband technology for automotive and smart device applications

March 10, 2026

Vect-Horus appoints Claudia Fromond as new Director of R&D

March 10, 2026
Facebook X (Twitter) Instagram
Finance Pro
Facebook X (Twitter) Instagram
Daily Guardian
Subscribe
  • Home
  • News
  • Politics
  • Business
  • Entertainment
  • Lifestyle
  • Health
  • Sports
  • Technology
  • Climate
  • Auto
  • Travel
  • Web Stories
Daily Guardian
Home » OpenClaw’s AI ‘skill’ extensions are a security nightmare
Technology

OpenClaw’s AI ‘skill’ extensions are a security nightmare

By News RoomFebruary 4, 20262 Mins Read
OpenClaw’s AI ‘skill’ extensions are a security nightmare
Share
Facebook Twitter LinkedIn Pinterest Email

OpenClaw, the AI agent that has exploded in popularity over the past week, is raising new security concerns after researchers uncovered malware in hundreds of user-submitted “skill” add-ons on its marketplace. In a post on Monday, 1Password product VP Jason Meller says OpenClaw’s skill hub has become “an attack surface,” with the most-downloaded add-on serving as a “malware delivery vehicle.”

OpenClaw — first called Clawdbot, then Moltbot — is billed as an AI agent that “actually does things,” such as managing your calendar, checking in for flights, cleaning out your inbox, and more. It runs locally on devices, and users can interact with the AI assistant through messaging apps like WhatsApp, Telegram, iMessage, and others. But some users are giving OpenClaw the ability to access their entire device, allowing it to read and write files, execute scripts, and run shell commands.

While this kind of access poses risks on its own, malware disguised as skills that are supposed to enhance OpenClaw’s capabilities only contribute to concerns. OpenSourceMalware, a platform that tracks the presence of malware across the open-source ecosystem, found that 28 malicious skills were published on the ClawHub skill marketplace between January 27th and 29th, in addition to 386 malicious add-ons that were uploaded between January 31st and February 2nd.

OpenSourceMalware says the skills “masquerade as cryptocurrency trading automation tools and deliver information-stealing malware” and manipulate users into executing malicious code that “steals crypto assets like exchange API keys, wallet private keys, SSH credentials, and browser passwords.”

Meller notes that OpenClaw’s skills are often uploaded as markdown files, which could contain malicious instructions for both users and the AI agent. That’s what he found when examining one of ClawHub’s most popular add-ons, a “Twitter” skill containing instructions for users to navigate to a link “designed to get the agent to run a command” that downloads infostealing malware.

OpenClaw’s creator, Peter Steinberger, is working to address some of these risks, as ClawHub now requires users to have a GitHub account that’s at least one week old to publish a skill. There’s also a new way to report skills, though this doesn’t remove the possibility of malware sneaking onto the platform.

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Keep Reading

‘Cash Apples’ is giving away $500,000 to people who click on trees in a web browser

One of this rugged phone’s cameras is a pop-out action cam

Apple Studio Display XDR review: a great, but expensive, pro option

You can get three months of Disney Plus and Hulu for $15 

Apple smart home display rumors now point to a fall launch with iOS 27

Bluesky CEO Jay Graber will step aside

Everything from the last week of everything is gambling now

Employees across OpenAI and Google support Anthropic’s lawsuit against the Pentagon

Apple’s new M5 Max feels like a huge upgrade if you bought your laptop 3 years ago

Editors Picks

Evolt Charging partners with AMPECO to support the next phase of EV Charging

March 10, 2026

Acronis Announces New #TeamUp Partnership in Switzerland with Hockey Club Davos AG and COOQIE

March 10, 2026

STMicroelectronics propels new era of ultra-wideband technology for automotive and smart device applications

March 10, 2026

Vect-Horus appoints Claudia Fromond as new Director of R&D

March 10, 2026

Latest News

Skyworks Demonstrates Advanced Connectivity and Power Solutions at Embedded World 2026

March 10, 2026

STARTRADER Supports UAE Labor Communities with Ramadan Iftar Initiative

March 10, 2026

Bitget Upgrades Agent Hub with Skills and CLI, Allowing OpenClaw to Start Trading in Three Minutes

March 10, 2026
Facebook X (Twitter) Pinterest TikTok Instagram
© 2026 Daily Guardian Canada. All Rights Reserved.
  • Privacy Policy
  • Terms
  • Advertise
  • Contact

Type above and press Enter to search. Press Esc to cancel.

Go to mobile version