Fetching from the wire…
Source-backed findings, relationship evidence, citations, and briefing history from the public MindPattern archive.
Snyk audit found 36% of ClawHub skills contain malicious components.
Source findingThe OpenClaw incident revealed 1,184 malicious skills across ClawHub.
Source findingOpenClaw v2026.3.22 ships with ClawHub as the default plugin registry replacing npm
Source findingSnyk found 36.82% of ClawHub skills contain security flaws.
Source findingClawHub registry for OpenClaw skills was poisoned at scale.
Source findingClawHub, Anthropic private marketplace, HappyCapy, OpenAI Frontier, and Notion all provide agent skills distribution platforms
Source findingClawForge governance layer addresses 12% malicious skill rate on ClawHub.
Source findingClawHub is OpenClaw's public marketplace for skills
Source findingSnyk audit found 36% of ClawHub skills contain malicious components.
Source findingThe OpenClaw incident revealed 1,184 malicious skills across ClawHub.
Source findingOpenClaw v2026.3.22 ships with ClawHub as the default plugin registry replacing npm
Source findingSnyk found 36.82% of ClawHub skills contain security flaws.
Source finding