Fetching from the wire…
Agents2026-09-14 · source-backed
This study scanned 66,192 public ClawHub skill versions and found 705 from 135 publishers that every scanner and the registry judge passed, yet which instruct actions prohibited by CIS Control 2.7 and NIST SP 800-53 CM-11. Hand-auditing 100 puts detector precision at 92%, with no sign of malicious intent, and one publisher contributes 506 of the 705. Separately, of 144 commands a live agent executed while following real skill documentation, 34.7% carried a consequence class the document never mentioned. Registry scanning answers "is this malicious," which is a different question from "is this permitted here, by this operator, right now." Their deterministic resolver with no model in the decision path stopped all 23 attempts across 53 already-cleared skills.
Each link below shares sources, entities, or timing with this story.
- Source: The Hacker News, Snyk - Category: deployment / security Koi Security audited 2,857 ClawHub skills: 341 malicious (12%), delivering Atomic Stealer malware targeting crypto wallets, SSH credentials, browser passwords across 9,000+ installations. Palo Alto Networks warn...
Koi Security found 820+ malicious skills on ClawHub (up from 335 in ClawHavoc days ago). Skills use professional docs and innocent names like "solana-wallet-tracker" then install keyloggers (Windows) or Atomic Stealer (macOS). Loaded skills inherit OpenClaw's full system permi...
arXiv 2607.25619 uses a regex prefilter that lets safe Markdown skill packages bypass the LLM judge entirely, sending only matched snippet windows for flagged files. On SkillsBench (n=1,650, 9.1% malicious) it hits 1.13% FPR and beats two existing tools by 5-6x on AUPRC. The t...
The first real supply chain attack on the agent instruction layer landed this week, and it's worse than the early reports suggested. A campaign dubbed ClawHavoc planted 1,184 malicious skills in ClawHub — OpenClaw's official skill marketplace — by embedding adversarial instruc...
The agent skills supply chain is under coordinated attack. Snyk's ToxicSkills audit found 36% of ClawHub's 3,984 skills contain prompt injection payloads, 13.4% have critical malware, and submission rates exploded 10x to 500+/day. This week alone: CVE-2026-2256 (CVSS 9.1) is a...
Defense-as-Skill argues pre-install vetting is structurally insufficient because a malicious skill only triggers once a concrete task and workspace state make the unsafe action look useful. SkillSonar runs as an editable skill alongside untrusted skills, checking sensitive act...
MindPattern daily
One email a day at 7 AM. Sources and a take on every story. Unsubscribe anytime.