Close Menu
Technophile NewsTechnophile News
  • Home
  • News
  • PC
  • Phones
  • Android
  • Gadgets
  • Games
  • Guides
  • Accessories
  • Reviews
  • Spotlight
  • More
    • Artificial Intelligence
    • Web Stories
    • Press Release
What's On
The Best Hearing Aids

The Best Hearing Aids

12 February 2026
The Fight Over US Climate Rules Is Just Beginning

The Fight Over US Climate Rules Is Just Beginning

12 February 2026
I Tried RentAHuman, Where AI Agents Hired Me to Hype Their AI Startups

I Tried RentAHuman, Where AI Agents Hired Me to Hype Their AI Startups

12 February 2026
Sony WF-1000XM6 earbuds review: the new noise-canceling king

Sony WF-1000XM6 earbuds review: the new noise-canceling king

12 February 2026
Alexa+ and Kindle Scribe Now Work Together With ‘Send to Alexa’

Alexa+ and Kindle Scribe Now Work Together With ‘Send to Alexa’

12 February 2026
Facebook X (Twitter) Instagram
  • Privacy
  • Terms
  • Advertise
  • Contact Us
Thursday, February 12
Facebook X (Twitter) Instagram YouTube
Technophile NewsTechnophile News
Demo
  • Home
  • News
  • PC
  • Phones
  • Android
  • Gadgets
  • Games
  • Guides
  • Accessories
  • Reviews
  • Spotlight
  • More
    • Artificial Intelligence
    • Web Stories
    • Press Release
Technophile NewsTechnophile News
Home » OpenClaw’s AI ‘skill’ extensions are a security nightmare
News

OpenClaw’s AI ‘skill’ extensions are a security nightmare

By News Room4 February 20262 Mins Read
Facebook Twitter Pinterest LinkedIn Telegram Tumblr Reddit WhatsApp Email
OpenClaw’s AI ‘skill’ extensions are a security nightmare
Share
Facebook Twitter LinkedIn Pinterest Email

OpenClaw, the AI agent that has exploded in popularity over the past week, is raising new security concerns after researchers uncovered malware in hundreds of user-submitted “skill” add-ons on its marketplace. In a post on Monday, 1Password product VP Jason Meller says OpenClaw’s skill hub has become “an attack surface,” with the most-downloaded add-on serving as a “malware delivery vehicle.”

OpenClaw — first called Clawdbot, then Moltbot — is billed as an AI agent that “actually does things,” such as managing your calendar, checking in for flights, cleaning out your inbox, and more. It runs locally on devices, and users can interact with the AI assistant through messaging apps like WhatsApp, Telegram, iMessage, and others. But some users are giving OpenClaw the ability to access their entire device, allowing it to read and write files, execute scripts, and run shell commands.

While this kind of access poses risks on its own, malware disguised as skills that are supposed to enhance OpenClaw’s capabilities only contribute to concerns. OpenSourceMalware, a platform that tracks the presence of malware across the open-source ecosystem, found that 28 malicious skills were published on the ClawHub skill marketplace between January 27th and 29th, in addition to 386 malicious add-ons that were uploaded between January 31st and February 2nd.

OpenSourceMalware says the skills “masquerade as cryptocurrency trading automation tools and deliver information-stealing malware” and manipulate users into executing malicious code that “steals crypto assets like exchange API keys, wallet private keys, SSH credentials, and browser passwords.”

Meller notes that OpenClaw’s skills are often uploaded as markdown files, which could contain malicious instructions for both users and the AI agent. That’s what he found when examining one of ClawHub’s most popular add-ons, a “Twitter” skill containing instructions for users to navigate to a link “designed to get the agent to run a command” that downloads infostealing malware.

OpenClaw’s creator, Peter Steinberger, is working to address some of these risks, as ClawHub now requires users to have a GitHub account that’s at least one week old to publish a skill. There’s also a new way to report skills, though this doesn’t remove the possibility of malware sneaking onto the platform.

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Related News

The Best Hearing Aids

The Best Hearing Aids

12 February 2026
The Fight Over US Climate Rules Is Just Beginning

The Fight Over US Climate Rules Is Just Beginning

12 February 2026
I Tried RentAHuman, Where AI Agents Hired Me to Hype Their AI Startups

I Tried RentAHuman, Where AI Agents Hired Me to Hype Their AI Startups

12 February 2026
Sony WF-1000XM6 earbuds review: the new noise-canceling king

Sony WF-1000XM6 earbuds review: the new noise-canceling king

12 February 2026
Alexa+ and Kindle Scribe Now Work Together With ‘Send to Alexa’

Alexa+ and Kindle Scribe Now Work Together With ‘Send to Alexa’

12 February 2026
Spider-Noir looks like a hard-boiled thriller in first trailer

Spider-Noir looks like a hard-boiled thriller in first trailer

12 February 2026
Top Articles
The CES 2026 stuff I might actually buy

The CES 2026 stuff I might actually buy

10 January 202660 Views
The Nex Playground and Pixel Buds 2A top our list of the best deals this week

The Nex Playground and Pixel Buds 2A top our list of the best deals this week

13 December 202549 Views
OpenAI Launches GPT-5.2 as It Navigates ‘Code Red’

OpenAI Launches GPT-5.2 as It Navigates ‘Code Red’

11 December 202546 Views
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Don't Miss
Spider-Noir looks like a hard-boiled thriller in first trailer

Spider-Noir looks like a hard-boiled thriller in first trailer

12 February 2026

Today, Amazon dropped a new trailer for its upcoming Spider-Noir starring Nicolas Cage as a…

The Asus Zenbook S 16 Is 0 Off and Has Never Been This Cheap

The Asus Zenbook S 16 Is $500 Off and Has Never Been This Cheap

12 February 2026
Ring cancels its partnership with Flock Safety after surveillance backlash

Ring cancels its partnership with Flock Safety after surveillance backlash

12 February 2026
‘Uncanny Valley’: ICE’s Secret Expansion Plans, Palantir Workers’ Ethical Concerns, and AI Assistants

‘Uncanny Valley’: ICE’s Secret Expansion Plans, Palantir Workers’ Ethical Concerns, and AI Assistants

12 February 2026
Technophile News
Facebook X (Twitter) Instagram Pinterest YouTube Dribbble
  • Privacy Policy
  • Terms of use
  • Advertise
  • Contact Us
© 2026 Technophile News. All Rights Reserved.

Type above and press Enter to search. Press Esc to cancel.