What the study found
Scanned 3,984 skills from ClawHub and skills.sh. Snyk confirmed 76 malicious payloads by hand and found 534 skills (13.4%) with at least one critical issue and 1,467 (36.82%) with any issue. Eight confirmed malicious skills were still installable on ClawHub at publication.
Techniques
- Prompt injection
- Credential theft
- Download piped to shell
Status, as stated by the source
A study, not a single listing. Eight confirmed malicious skills were live at publication; current status not stated.
We do not check the registry ourselves. “Unknown” means no source we found says the skill was removed.
Would Ironheights flag this pattern?
Not assessed
A measurement across many skills. We have not mapped its findings to individual rules.
Sources
- Snyk Finds Prompt Injection in 36%, 1467 Malicious Payloads in a ToxicSkills Study of Agent Skills(opens in a new tab)Snyk · primary
- Exploring the Threat Landscape of Agent Skills(opens in a new tab)Snyk Labs · primaryResearch write-up of the same study.
Sources are the only outbound links on this page. We never link to the skills themselves or publish their payloads.
Related reports
- soroban-trader-skill and burhanclaw-soroban-traderCommunity report on GitHub (Rayzar) · 14 April 2026Skill
- omnicogg (22 MB padded README)JFrog Security Research · 6 March 2026Skill
- Bitdefender Labs analysis of OpenClaw skillsBitdefender Labs · 5 February 2026Study
Related rules
No rule is mapped to this entry. Browse all rules in the rules reference, and read Limitations for what a skill scanner cannot see.