Canadian ReviewsCanadian Reviews
  • What’s On
  • Reviews
  • Digital World
  • Lifestyle
  • Travel
  • Trending
  • Web Stories
Trending Now
Where is Artemis 2 now? Live track NASA’s moon mission

Where is Artemis 2 now? Live track NASA’s moon mission

Toronto’s best bagels, Canada Reviews

Toronto’s best bagels, Canada Reviews

Hilton to Open Over 100 Hotels in Africa, Expanding in Sub-Saharan Markets

Hilton to Open Over 100 Hotels in Africa, Expanding in Sub-Saharan Markets

This cyberpunk Steam action game already looks incredible

This cyberpunk Steam action game already looks incredible

The '70s Flash Gordon Now & Later Collab Is the Greatest Forgotten Piece of Candy History

The '70s Flash Gordon Now & Later Collab Is the Greatest Forgotten Piece of Candy History

I saved a doomed Windows laptop by embracing Linux

I saved a doomed Windows laptop by embracing Linux

3rd Apr: The Sisterhood of the Traveling Pants (2005), 1hr 58m [PG] – Streaming Again (6.25/10)

3rd Apr: The Sisterhood of the Traveling Pants (2005), 1hr 58m [PG] – Streaming Again (6.25/10)

Facebook X (Twitter) Instagram
  • Privacy
  • Terms
  • Advertise
  • Contact us
Facebook X (Twitter) Instagram Pinterest Vimeo
Canadian ReviewsCanadian Reviews
  • What’s On
  • Reviews
  • Digital World
  • Lifestyle
  • Travel
  • Trending
  • Web Stories
Newsletter
Canadian ReviewsCanadian Reviews
You are at:Home » OpenClaw’s AI ‘skill’ extensions are a security nightmare
OpenClaw’s AI ‘skill’ extensions are a security nightmare
Digital World

OpenClaw’s AI ‘skill’ extensions are a security nightmare

4 February 20262 Mins Read

OpenClaw, the AI agent that has exploded in popularity over the past week, is raising new security concerns after researchers uncovered malware in hundreds of user-submitted “skill” add-ons on its marketplace. In a post on Monday, 1Password product VP Jason Meller says OpenClaw’s skill hub has become “an attack surface,” with the most-downloaded add-on serving as a “malware delivery vehicle.”

OpenClaw — first called Clawdbot, then Moltbot — is billed as an AI agent that “actually does things,” such as managing your calendar, checking in for flights, cleaning out your inbox, and more. It runs locally on devices, and users can interact with the AI assistant through messaging apps like WhatsApp, Telegram, iMessage, and others. But some users are giving OpenClaw the ability to access their entire device, allowing it to read and write files, execute scripts, and run shell commands.

While this kind of access poses risks on its own, malware disguised as skills that are supposed to enhance OpenClaw’s capabilities only contribute to concerns. OpenSourceMalware, a platform that tracks the presence of malware across the open-source ecosystem, found that 28 malicious skills were published on the ClawHub skill marketplace between January 27th and 29th, in addition to 386 malicious add-ons that were uploaded between January 31st and February 2nd.

OpenSourceMalware says the skills “masquerade as cryptocurrency trading automation tools and deliver information-stealing malware” and manipulate users into executing malicious code that “steals crypto assets like exchange API keys, wallet private keys, SSH credentials, and browser passwords.”

Meller notes that OpenClaw’s skills are often uploaded as markdown files, which could contain malicious instructions for both users and the AI agent. That’s what he found when examining one of ClawHub’s most popular add-ons, a “Twitter” skill containing instructions for users to navigate to a link “designed to get the agent to run a command” that downloads infostealing malware.

OpenClaw’s creator, Peter Steinberger, is working to address some of these risks, as ClawHub now requires users to have a GitHub account that’s at least one week old to publish a skill. There’s also a new way to report skills, though this doesn’t remove the possibility of malware sneaking onto the platform.

Share. Facebook Twitter Pinterest LinkedIn Reddit WhatsApp Telegram Email

Related Articles

I saved a doomed Windows laptop by embracing Linux

I saved a doomed Windows laptop by embracing Linux

Digital World 3 April 2026
How the Apple Watch defined modern health tech

How the Apple Watch defined modern health tech

Digital World 3 April 2026
Apple’s best product ever

Apple’s best product ever

Digital World 3 April 2026
Chatbots are now prescribing psychiatric drugs

Chatbots are now prescribing psychiatric drugs

Digital World 3 April 2026
Reddit is moving on from r/all

Reddit is moving on from r/all

Digital World 2 April 2026
PSA: Anyone with a link can view your Granola notes by default

PSA: Anyone with a link can view your Granola notes by default

Digital World 2 April 2026
Top Articles
As an ER doc and a mom. Here are five things I don’t let my kids do because the risks are too high | Canada Voices

As an ER doc and a mom. Here are five things I don’t let my kids do because the risks are too high | Canada Voices

11 January 2026257 Views
9 Longest-Lasting Nail Polishes, Tested by Top Manicurists

9 Longest-Lasting Nail Polishes, Tested by Top Manicurists

25 January 2026179 Views
Canada’s best employers for 2026 were revealed and these are the top companies to work for

Canada’s best employers for 2026 were revealed and these are the top companies to work for

21 January 202699 Views
Forbes ranked Canada’s top employers for 2026 and over 30 Quebec companies made the cut

Forbes ranked Canada’s top employers for 2026 and over 30 Quebec companies made the cut

22 January 202697 Views
Demo
Don't Miss
I saved a doomed Windows laptop by embracing Linux
Digital World 3 April 2026

I saved a doomed Windows laptop by embracing Linux

Two weeks ago I set aside my M4 MacBook Air and picked up a nine-year-old…

3rd Apr: The Sisterhood of the Traveling Pants (2005), 1hr 58m [PG] – Streaming Again (6.25/10)

3rd Apr: The Sisterhood of the Traveling Pants (2005), 1hr 58m [PG] – Streaming Again (6.25/10)

10 best day trips from Toronto this spring, Canada Reviews

10 best day trips from Toronto this spring, Canada Reviews

Amazon hiking some prices; blames higher fuel costs

Amazon hiking some prices; blames higher fuel costs

About Us
About Us

Canadian Reviews is your one-stop website for the latest Canadian trends and things to do, follow us now to get the news that matters to you.

Facebook X (Twitter) Pinterest YouTube WhatsApp
Our Picks
Where is Artemis 2 now? Live track NASA’s moon mission

Where is Artemis 2 now? Live track NASA’s moon mission

Toronto’s best bagels, Canada Reviews

Toronto’s best bagels, Canada Reviews

Hilton to Open Over 100 Hotels in Africa, Expanding in Sub-Saharan Markets

Hilton to Open Over 100 Hotels in Africa, Expanding in Sub-Saharan Markets

Most Popular
Why You Should Consider Investing with IC Markets

Why You Should Consider Investing with IC Markets

28 April 202430 Views
OANDA Review – Low costs and no deposit requirements

OANDA Review – Low costs and no deposit requirements

28 April 2024364 Views
LearnToTrade: A Comprehensive Look at the Controversial Trading School

LearnToTrade: A Comprehensive Look at the Controversial Trading School

28 April 202480 Views
© 2026 ThemeSphere. Designed by ThemeSphere.
  • Privacy Policy
  • Terms of use
  • Advertise
  • Contact us

Type above and press Enter to search. Press Esc to cancel.