Close Menu
Canadian ReviewsCanadian Reviews
  • What’s On
  • Reviews
  • Digital World
  • Lifestyle
  • Travel
  • Trending
  • Web Stories
Trending Now
North America’s largest Hong Kong festival will take over Metro Vancouver for one day only

North America’s largest Hong Kong festival will take over Metro Vancouver for one day only

Local bookstores in Edmonton to indulge in your reading fantasies

Local bookstores in Edmonton to indulge in your reading fantasies

Multiple arrests made in downtown LA after sex toys thrown during anti-ICE protest, officials say

Multiple arrests made in downtown LA after sex toys thrown during anti-ICE protest, officials say

6 things you should know about Christine Fréchette, Quebec’s new premier

6 things you should know about Christine Fréchette, Quebec’s new premier

Four Seasons Hotel Kuala Lumpur Launches AI Technologies for Meetings and Events

Four Seasons Hotel Kuala Lumpur Launches AI Technologies for Meetings and Events

Former senator to be interim head of RCMP watchdog

Former senator to be interim head of RCMP watchdog

Mark Zuckerberg is reportedly building an AI clone to replace him in meetings

Mark Zuckerberg is reportedly building an AI clone to replace him in meetings

Facebook X (Twitter) Instagram
  • Privacy
  • Terms
  • Advertise
  • Contact us
Facebook X (Twitter) Instagram Pinterest Vimeo
Canadian ReviewsCanadian Reviews
  • What’s On
  • Reviews
  • Digital World
  • Lifestyle
  • Travel
  • Trending
  • Web Stories
Newsletter
Canadian ReviewsCanadian Reviews
You are at:Home » OpenClaw’s AI ‘skill’ extensions are a security nightmare
OpenClaw’s AI ‘skill’ extensions are a security nightmare
Digital World

OpenClaw’s AI ‘skill’ extensions are a security nightmare

4 February 20262 Mins Read

OpenClaw, the AI agent that has exploded in popularity over the past week, is raising new security concerns after researchers uncovered malware in hundreds of user-submitted “skill” add-ons on its marketplace. In a post on Monday, 1Password product VP Jason Meller says OpenClaw’s skill hub has become “an attack surface,” with the most-downloaded add-on serving as a “malware delivery vehicle.”

OpenClaw — first called Clawdbot, then Moltbot — is billed as an AI agent that “actually does things,” such as managing your calendar, checking in for flights, cleaning out your inbox, and more. It runs locally on devices, and users can interact with the AI assistant through messaging apps like WhatsApp, Telegram, iMessage, and others. But some users are giving OpenClaw the ability to access their entire device, allowing it to read and write files, execute scripts, and run shell commands.

While this kind of access poses risks on its own, malware disguised as skills that are supposed to enhance OpenClaw’s capabilities only contribute to concerns. OpenSourceMalware, a platform that tracks the presence of malware across the open-source ecosystem, found that 28 malicious skills were published on the ClawHub skill marketplace between January 27th and 29th, in addition to 386 malicious add-ons that were uploaded between January 31st and February 2nd.

OpenSourceMalware says the skills “masquerade as cryptocurrency trading automation tools and deliver information-stealing malware” and manipulate users into executing malicious code that “steals crypto assets like exchange API keys, wallet private keys, SSH credentials, and browser passwords.”

Meller notes that OpenClaw’s skills are often uploaded as markdown files, which could contain malicious instructions for both users and the AI agent. That’s what he found when examining one of ClawHub’s most popular add-ons, a “Twitter” skill containing instructions for users to navigate to a link “designed to get the agent to run a command” that downloads infostealing malware.

OpenClaw’s creator, Peter Steinberger, is working to address some of these risks, as ClawHub now requires users to have a GitHub account that’s at least one week old to publish a skill. There’s also a new way to report skills, though this doesn’t remove the possibility of malware sneaking onto the platform.

Share. Facebook Twitter Pinterest LinkedIn Reddit WhatsApp Telegram Email

Related Articles

Mark Zuckerberg is reportedly building an AI clone to replace him in meetings

Mark Zuckerberg is reportedly building an AI clone to replace him in meetings

Digital World 13 April 2026
SwitchBot’s button-pressing robot is now available with a rechargeable battery

SwitchBot’s button-pressing robot is now available with a rechargeable battery

Digital World 13 April 2026
The Puck CEO’s quest to reinvent the news business in the influencer age

The Puck CEO’s quest to reinvent the news business in the influencer age

Digital World 13 April 2026
Huawei beats Apple and Samsung with new wide foldable

Huawei beats Apple and Samsung with new wide foldable

Digital World 13 April 2026
Did Neuralink make the wrong bet?

Did Neuralink make the wrong bet?

Digital World 13 April 2026
Microsoft’s new Xbox Gamepad Cursor adds a virtual mouse to handhelds

Microsoft’s new Xbox Gamepad Cursor adds a virtual mouse to handhelds

Digital World 13 April 2026
Top Articles
9 Longest-Lasting Nail Polishes, Tested by Top Manicurists

9 Longest-Lasting Nail Polishes, Tested by Top Manicurists

25 January 2026179 Views
Forbes ranked Canada’s top employers for 2026 and over 30 Quebec companies made the cut

Forbes ranked Canada’s top employers for 2026 and over 30 Quebec companies made the cut

22 January 202699 Views
Canada’s best employers for 2026 were revealed and these are the top companies to work for

Canada’s best employers for 2026 were revealed and these are the top companies to work for

21 January 202698 Views
The Mother May I Story – Chickpea Edition

The Mother May I Story – Chickpea Edition

18 May 202497 Views
Demo
Don't Miss
Former senator to be interim head of RCMP watchdog
Lifestyle 13 April 2026

Former senator to be interim head of RCMP watchdog

The Liberal government has named well-known legal ethicist and former senator Brent Cotter to be…

Mark Zuckerberg is reportedly building an AI clone to replace him in meetings

Mark Zuckerberg is reportedly building an AI clone to replace him in meetings

A new Southern Thai street tea stall is hand-pulling drinks near the Eaton Centre, Canada Reviews

A new Southern Thai street tea stall is hand-pulling drinks near the Eaton Centre, Canada Reviews

I moved to Canada after it topped global rankings, but I wasn’t prepared for what came next, Life in canada

I moved to Canada after it topped global rankings, but I wasn’t prepared for what came next, Life in canada

About Us
About Us

Canadian Reviews is your one-stop website for the latest Canadian trends and things to do, follow us now to get the news that matters to you.

Facebook X (Twitter) Pinterest YouTube WhatsApp
Our Picks
North America’s largest Hong Kong festival will take over Metro Vancouver for one day only

North America’s largest Hong Kong festival will take over Metro Vancouver for one day only

Local bookstores in Edmonton to indulge in your reading fantasies

Local bookstores in Edmonton to indulge in your reading fantasies

Multiple arrests made in downtown LA after sex toys thrown during anti-ICE protest, officials say

Multiple arrests made in downtown LA after sex toys thrown during anti-ICE protest, officials say

Most Popular
Why You Should Consider Investing with IC Markets

Why You Should Consider Investing with IC Markets

28 April 202429 Views
OANDA Review – Low costs and no deposit requirements

OANDA Review – Low costs and no deposit requirements

28 April 2024362 Views
LearnToTrade: A Comprehensive Look at the Controversial Trading School

LearnToTrade: A Comprehensive Look at the Controversial Trading School

28 April 202476 Views
© 2026 ThemeSphere. Designed by ThemeSphere.
  • Privacy Policy
  • Terms of use
  • Advertise
  • Contact us

Type above and press Enter to search. Press Esc to cancel.