What is OpenClaw skill supply-chain risk?
Why skills are a supply chain
Every skill you install is a dependency. You trust its author, the marketplace that hosted it, every update after your review, and anything it fetches while it runs. That is the same chain of trust as a software package, with two differences that make it sharper.
First, the artifact is language. A skill can be harmful without containing code, because the agent follows its instructions. Second, the privilege is high. A skill inherits whatever the agent can do, which often includes a shell, email, source code, cloud accounts or a wallet.
Where the risk enters
- At publish time. A malicious author publishes a lookalike or a useful-sounding skill. Public reports counted hundreds in early 2026.
- Through dependencies. The skill tells you to install a "required" tool from a website or archive. The tool is the payload.
- After review. The skill updates, or a file in your workspace changes, and the version you vetted is no longer the version you run.
- At runtime. The skill fetches instructions or data from a server on every use, so its behavior can change without any file changing. Unit 42 described a skill that rotated affiliate links this way.
- Through popularity. Download counts are not a safety signal; JFrog reported over 5,000 downloads in 19 days for one padded dropper.
Who is most exposed
Small teams and agencies that let agents touch email, source code, customer data, cloud accounts or crypto carry the most risk, because one bad skill reaches all of it. A solo user with a sandboxed agent and no real credentials carries far less. The first question to ask is not "is this skill safe?" but "what could it reach if it were not?"
How to reduce it
Treat it the way mature teams treat package risk:
- Vet before install. Use a checklist and a scanner such as the browser scanner or
npx ironheights scan. - Pin and re-vet. Re-check a skill on every update instead of trusting the publisher forever.
- Detect drift. Record a baseline and run
ironheights verifyto see added, modified or removed files. See how to check if a skill changed. - Limit access. Run new skills in an agent without production credentials.
- Watch the reports. Our malicious skill tracker collects public cases with sources.
Limits
A file scanner covers the first and third points only partly. It cannot see payloads on linked websites or behavior that changes at runtime. See the limitations page.
Sources
- OpenClaw's Skill Marketplace and the Emerging AI Supply Chain Threat, Palo Alto Networks Unit 42, 23 June 2026.
- Exploring the Threat Landscape of Agent Skills, Snyk Labs, 5 February 2026.
- Anatomy of a Deception: the 'omnicogg' Dropper, JFrog Security Research.
- Researchers Find 341 Malicious ClawHub Skills, The Hacker News.