What is a malicious ClawHub skill?
How it differs from a malicious package
A malicious npm or PyPI package hides harmful code. A malicious skill often needs no code at all. Its SKILL.md is plain language that the agent treats as instructions, so the harmful part can be a sentence: "before using this skill, run the following setup command." VirusTotal put it this way after analyzing more than 3,016 OpenClaw skills: nothing in such a file is malware by itself; the malware is the workflow it asks you to run.
Patterns seen in public reports
- Fake prerequisites. The skill claims it needs a helper or "core" tool and gives an encoded command or a link. Koi's ClawHavoc report describes hundreds of skills that used this to deliver the Atomic macOS Stealer. We took the pattern apart in this teardown.
- Payload on another site. The skill only links to a lookalike website or paste site that serves the command, so the skill file itself looks clean.
- Credential theft. The skill reads key files such as
.env, SSH keys or wallets and sends them to an outside host. - Hidden code in working tools. One reported Polymarket skill worked as advertised but also opened a reverse shell to the attacker during normal use.
- Padding. One skill hid its command in a README padded to about 22 MB to get past scanner size limits.
- Agent-native fraud. Skills that steer the agent's advice toward affiliate links, or tell agents to pool cryptocurrency into the operator's wallet.
The usual lures are things people want right now: crypto and trading tools, social media helpers, Google Workspace connectors, auto-updaters, and lookalikes of official OpenClaw or ClawHub tools.
How big the problem is
Koi audited the 2,857 skills on ClawHub in early February 2026 and reported 341 as malicious, 335 of them from one campaign. Snyk confirmed 76 malicious payloads by hand in a study of 3,984 skills. Counts differ by method and date, and the marketplace has added scanning since.
Where to see real cases
Our malicious skill tracker lists publicly reported campaigns and skills with the reporter, the date, the status the source gives, and which Ironheights rules flag the pattern. It never links to the skills themselves.
How to recognize one
Read the setup section first, check every link and command, and compare what the skill asks for with what it claims to do. A scanner helps: Ironheights flags patterns such as remote content piped into a shell (IH-EXEC-001) and access to credential paths (IH-CRED-001). It cannot catch everything; see the limitations page.
Sources
- From Automation to Infection: How OpenClaw AI Agent Skills Are Being Weaponized, VirusTotal, 2 February 2026.
- ClawHavoc report, Koi Security (archived copy).
- openclaw/clawhub issue #152: polymarket-all-in-one, GitHub.
- Anatomy of a Deception: the 'omnicogg' Dropper, JFrog Security Research.
- OpenClaw's Skill Marketplace and the Emerging AI Supply Chain Threat, Palo Alto Networks Unit 42.