OpenClaw, an AI agent ecosystem formerly known as Clawdbot and Moltbot, presents significant security risks to users and organizations due to vulnerabilities and the widespread distribution of malicious extensions. The platform's popularity stems from its flexibility and ability to automate complex tasks using natural language instructions without requiring programming knowledge. This ease of use, however, has attracted attackers who exploit its architecture and the availability of third-party "skills" – sets of commands that extend the agent's capabilities.
These skills, often shared through a hub called ClawHub, can be created easily and do not necessarily require coding, typically existing as plaintext files. While intended for tasks ranging from email management to software development, their design allows them to access the operating system's file system and interact with system tokens and keys. This access is often granted by users who provide necessary data through environment variables or plaintext files alongside the agent.
Since February 2026, approximately 530 vulnerabilities have been documented in OpenClaw and its underlying technologies, with a notable number classified as high-severity. These issues primarily concern the insecure storage of sensitive data and the granting of excessive privileges, which can be exploited to hijack the agent or force it to execute unauthorized commands.
A significant threat vector involves malicious skills, which researchers liken to supply-chain attacks. The ease of skill creation means attackers can distribute harmful code disguised as legitimate tools. Until early February 2026, there was no formal security vetting for skills uploaded to the hub. Investigations in April revealed that at least 24 accounts were distributing over 600 malicious skills, with open-source intelligence indicating the creation of over 1100 malicious accounts since January.
Following these discoveries, measures were implemented to scan uploaded skills using VirusTotal and NVIDIA's SkillSpector. However, the nature of OpenClaw as an instruction-executing agent means that detecting malicious activity requires not only analyzing files for dangerous commands but also examining potential harmful behaviors triggered by seemingly innocuous instructions.
Kaspersky products have detected malicious OpenClaw skill activity, identifying certain malicious skills as HEUR:Trojan.ANSI.MalClaw.gen. Statistics from their systems show that attacks continue even after the implementation of countermeasures against malicious skill publications.
To mitigate these risks, a layered security approach is recommended. This includes isolating the OpenClaw agent from critical data and infrastructure systems. Organizations should also vet all skills before they are introduced into their environment, with solutions like Kaspersky Scan Engine being suitable for this purpose.
Monitoring the network access patterns of the agent is also crucial. OpenClaw offers a sandboxing subsystem and wrappers for service interactions that can aid in this. Finally, establishing a comprehensive AI policy and ensuring employees do not use unapproved third-party tools are essential steps in protecting against these threats.






