Canadian ReviewsCanadian Reviews
  • What’s On
  • Reviews
  • Digital World
  • Lifestyle
  • Travel
  • Trending
  • Web Stories
Trending Now
There will be free Latin dance lessons in Edmonton’s Churchill Square all through spring

There will be free Latin dance lessons in Edmonton’s Churchill Square all through spring

A new year-round outdoor skating rink has officially opened in Calgary

A new year-round outdoor skating rink has officially opened in Calgary

Maximizing Property Value through Modern Kitchen Design, Canada Reviews

Maximizing Property Value through Modern Kitchen Design, Canada Reviews

4th May: Dr. Seuss's Horton! (2026), 2 Seasons [TV-Y] – New Episodes (6/10)

4th May: Dr. Seuss's Horton! (2026), 2 Seasons [TV-Y] – New Episodes (6/10)

Trump teases release of “very interesting” UFO files

Trump teases release of “very interesting” UFO files

Amazon’s trying to turn its massive shipping operation into another AWS

Amazon’s trying to turn its massive shipping operation into another AWS

Montreal’s viral pothole fixer just launched a GoFundMe and it’s already raised nearly K

Montreal’s viral pothole fixer just launched a GoFundMe and it’s already raised nearly $30K

Facebook X (Twitter) Instagram
  • Privacy
  • Terms
  • Advertise
  • Contact us
Facebook X (Twitter) Instagram Pinterest Vimeo
Canadian ReviewsCanadian Reviews
  • What’s On
  • Reviews
  • Digital World
  • Lifestyle
  • Travel
  • Trending
  • Web Stories
Newsletter
Canadian ReviewsCanadian Reviews
You are at:Home » OpenClaw’s AI ‘skill’ extensions are a security nightmare
OpenClaw’s AI ‘skill’ extensions are a security nightmare
Digital World

OpenClaw’s AI ‘skill’ extensions are a security nightmare

4 February 20262 Mins Read

OpenClaw, the AI agent that has exploded in popularity over the past week, is raising new security concerns after researchers uncovered malware in hundreds of user-submitted “skill” add-ons on its marketplace. In a post on Monday, 1Password product VP Jason Meller says OpenClaw’s skill hub has become “an attack surface,” with the most-downloaded add-on serving as a “malware delivery vehicle.”

OpenClaw — first called Clawdbot, then Moltbot — is billed as an AI agent that “actually does things,” such as managing your calendar, checking in for flights, cleaning out your inbox, and more. It runs locally on devices, and users can interact with the AI assistant through messaging apps like WhatsApp, Telegram, iMessage, and others. But some users are giving OpenClaw the ability to access their entire device, allowing it to read and write files, execute scripts, and run shell commands.

While this kind of access poses risks on its own, malware disguised as skills that are supposed to enhance OpenClaw’s capabilities only contribute to concerns. OpenSourceMalware, a platform that tracks the presence of malware across the open-source ecosystem, found that 28 malicious skills were published on the ClawHub skill marketplace between January 27th and 29th, in addition to 386 malicious add-ons that were uploaded between January 31st and February 2nd.

OpenSourceMalware says the skills “masquerade as cryptocurrency trading automation tools and deliver information-stealing malware” and manipulate users into executing malicious code that “steals crypto assets like exchange API keys, wallet private keys, SSH credentials, and browser passwords.”

Meller notes that OpenClaw’s skills are often uploaded as markdown files, which could contain malicious instructions for both users and the AI agent. That’s what he found when examining one of ClawHub’s most popular add-ons, a “Twitter” skill containing instructions for users to navigate to a link “designed to get the agent to run a command” that downloads infostealing malware.

OpenClaw’s creator, Peter Steinberger, is working to address some of these risks, as ClawHub now requires users to have a GitHub account that’s at least one week old to publish a skill. There’s also a new way to report skills, though this doesn’t remove the possibility of malware sneaking onto the platform.

Share. Facebook Twitter Pinterest LinkedIn Reddit WhatsApp Telegram Email

Related Articles

Amazon’s trying to turn its massive shipping operation into another AWS

Amazon’s trying to turn its massive shipping operation into another AWS

Digital World 4 May 2026
Tesla hits Musk’s threshold for ‘safe unsupervised’ driving

Tesla hits Musk’s threshold for ‘safe unsupervised’ driving

Digital World 4 May 2026
Hisense aggressively cuts the price of its RGB LED TV on release day

Hisense aggressively cuts the price of its RGB LED TV on release day

Digital World 4 May 2026
These digital Polaroids are a clever way to cover a fridge in memories

These digital Polaroids are a clever way to cover a fridge in memories

Digital World 3 May 2026
Shokz’s bassy OpenRun Pro 2 are  off thanks to a new Mother’s Day promo

Shokz’s bassy OpenRun Pro 2 are $40 off thanks to a new Mother’s Day promo

Digital World 3 May 2026
Reggie Fils-Aimé says Amazon once asked Nintendo to break the law

Reggie Fils-Aimé says Amazon once asked Nintendo to break the law

Digital World 3 May 2026
Top Articles
Grace Gummer, Meryl Streep’s Daughter, Owns the Red Carpet After Haunting Portrayal of Caroline Kennedy

Grace Gummer, Meryl Streep’s Daughter, Owns the Red Carpet After Haunting Portrayal of Caroline Kennedy

15 April 2026234 Views
Canada’s ‘most beautiful’ university campuses were revealed and so many are by water

Canada’s ‘most beautiful’ university campuses were revealed and so many are by water

15 April 2026104 Views
Anita Rochon, director of A Doll’s House at Theatre Calgary, knows a good play has your back

Anita Rochon, director of A Doll’s House at Theatre Calgary, knows a good play has your back

14 April 202697 Views
The Mother May I Story – Chickpea Edition

The Mother May I Story – Chickpea Edition

18 May 202497 Views
Demo
Don't Miss
Amazon’s trying to turn its massive shipping operation into another AWS
Digital World 4 May 2026

Amazon’s trying to turn its massive shipping operation into another AWS

Amazon might have a part in delivering all kinds of stuff to your door soon,…

Montreal’s viral pothole fixer just launched a GoFundMe and it’s already raised nearly K

Montreal’s viral pothole fixer just launched a GoFundMe and it’s already raised nearly $30K

The ultimate Toronto deli crawl with one of the city’s top foodies, Canada Reviews

The ultimate Toronto deli crawl with one of the city’s top foodies, Canada Reviews

Weekly Pause and Ponder, Theater News

Weekly Pause and Ponder, Theater News

About Us
About Us

Canadian Reviews is your one-stop website for the latest Canadian trends and things to do, follow us now to get the news that matters to you.

Facebook X (Twitter) Pinterest YouTube WhatsApp
Our Picks
There will be free Latin dance lessons in Edmonton’s Churchill Square all through spring

There will be free Latin dance lessons in Edmonton’s Churchill Square all through spring

A new year-round outdoor skating rink has officially opened in Calgary

A new year-round outdoor skating rink has officially opened in Calgary

Maximizing Property Value through Modern Kitchen Design, Canada Reviews

Maximizing Property Value through Modern Kitchen Design, Canada Reviews

Most Popular
Why You Should Consider Investing with IC Markets

Why You Should Consider Investing with IC Markets

28 April 202431 Views
OANDA Review – Low costs and no deposit requirements

OANDA Review – Low costs and no deposit requirements

28 April 2024367 Views
LearnToTrade: A Comprehensive Look at the Controversial Trading School

LearnToTrade: A Comprehensive Look at the Controversial Trading School

28 April 202484 Views
© 2026 ThemeSphere. Designed by ThemeSphere.
  • Privacy Policy
  • Terms of use
  • Advertise
  • Contact us

Type above and press Enter to search. Press Esc to cancel.