OpenClaw skill security
Teardowns of malicious ClawHub skills, hardening guides for OpenClaw, and notes on how the Ironheights rules work and where they miss.
Ironheights is a local-first scanner for OpenClaw skills. See what it detects and what it cannot.
- ReleaseIronheights 0.3.0 adds ironheights coexist, which finds other scanners and guards on your agent and reports overlaps. How it works, and where it stops.Read
- ReleaseIronheights 0.2.0 adds fetch and safe-install, signed baselines, a guard plugin for agent tool calls, an A to F grade and advisory feed support. Plain language.Read
- LimitsWhat Ironheights misses: payloads on linked sites, files over 1 MiB, runtime behavior, money-moving instructions and a compromised host, with a fix for each.Read
- GuideHow to record a known-good baseline of OpenClaw skills and agent files like AGENTS.md, SOUL.md and MEMORY.md, and verify later what was added, modified or removed.Read
- GuideThe quiet places an OpenClaw agent exposes API keys, SSH keys and wallets: chat, memory, .env files, skill files and outbound requests. How to check each.Read
- ArchitectureA security skill shares the agent's context with the skills it checks, so a hostile skill can talk the agent out of it. Where the real trust boundary is.Read
- GuideA 10-minute routine to vet an OpenClaw or ClawHub skill before install: where it comes from, what to read in SKILL.md, what it can reach, what to record.Read
- TeardownHow fake 'Prerequisites' sections in ClawHub skills get agents and people to run malware, the variants seen in 2026, and what a file scanner can and cannot see.Read