Close Menu
Canadian ReviewsCanadian Reviews
  • What’s On
  • Reviews
  • Digital World
  • Lifestyle
  • Travel
  • Trending
  • Web Stories
Trending Now
19th Apr: Notting Hill (1999), 2hr 4m [PG-13] – Streaming Again (6.6/10)

19th Apr: Notting Hill (1999), 2hr 4m [PG-13] – Streaming Again (6.6/10)

Kicking off your Sunday shoes: Footloose at the Mayfield, a review, Theater News

Kicking off your Sunday shoes: Footloose at the Mayfield, a review, Theater News

All The Netflix Originals Leaving Netflix in April and May 2026

All The Netflix Originals Leaving Netflix in April and May 2026

Carney pledges regular updates on pivot from U.S.

Carney pledges regular updates on pivot from U.S.

11 Canadian snacks you can’t find in the US so I just dream about now, Life in canada

11 Canadian snacks you can’t find in the US so I just dream about now, Life in canada

“Giant” and the Weight of Words That Cannot Be Taken Back – front mezz junkies, Theater News

“Giant” and the Weight of Words That Cannot Be Taken Back – front mezz junkies, Theater News

Safeguarding Your Website — BigScoots

Facebook X (Twitter) Instagram
  • Privacy
  • Terms
  • Advertise
  • Contact us
Facebook X (Twitter) Instagram Pinterest Vimeo
Canadian ReviewsCanadian Reviews
  • What’s On
  • Reviews
  • Digital World
  • Lifestyle
  • Travel
  • Trending
  • Web Stories
Newsletter
Canadian ReviewsCanadian Reviews
You are at:Home » OpenClaw’s AI ‘skill’ extensions are a security nightmare
OpenClaw’s AI ‘skill’ extensions are a security nightmare
Digital World

OpenClaw’s AI ‘skill’ extensions are a security nightmare

4 February 20262 Mins Read

OpenClaw, the AI agent that has exploded in popularity over the past week, is raising new security concerns after researchers uncovered malware in hundreds of user-submitted “skill” add-ons on its marketplace. In a post on Monday, 1Password product VP Jason Meller says OpenClaw’s skill hub has become “an attack surface,” with the most-downloaded add-on serving as a “malware delivery vehicle.”

OpenClaw — first called Clawdbot, then Moltbot — is billed as an AI agent that “actually does things,” such as managing your calendar, checking in for flights, cleaning out your inbox, and more. It runs locally on devices, and users can interact with the AI assistant through messaging apps like WhatsApp, Telegram, iMessage, and others. But some users are giving OpenClaw the ability to access their entire device, allowing it to read and write files, execute scripts, and run shell commands.

While this kind of access poses risks on its own, malware disguised as skills that are supposed to enhance OpenClaw’s capabilities only contribute to concerns. OpenSourceMalware, a platform that tracks the presence of malware across the open-source ecosystem, found that 28 malicious skills were published on the ClawHub skill marketplace between January 27th and 29th, in addition to 386 malicious add-ons that were uploaded between January 31st and February 2nd.

OpenSourceMalware says the skills “masquerade as cryptocurrency trading automation tools and deliver information-stealing malware” and manipulate users into executing malicious code that “steals crypto assets like exchange API keys, wallet private keys, SSH credentials, and browser passwords.”

Meller notes that OpenClaw’s skills are often uploaded as markdown files, which could contain malicious instructions for both users and the AI agent. That’s what he found when examining one of ClawHub’s most popular add-ons, a “Twitter” skill containing instructions for users to navigate to a link “designed to get the agent to run a command” that downloads infostealing malware.

OpenClaw’s creator, Peter Steinberger, is working to address some of these risks, as ClawHub now requires users to have a GitHub account that’s at least one week old to publish a skill. There’s also a new way to report skills, though this doesn’t remove the possibility of malware sneaking onto the platform.

Share. Facebook Twitter Pinterest LinkedIn Reddit WhatsApp Telegram Email

Related Articles

Marathon battery life makes Keychron’s Ultra 8K keyboards its best yet

Marathon battery life makes Keychron’s Ultra 8K keyboards its best yet

Digital World 19 April 2026
The RAM shortage could last years

The RAM shortage could last years

Digital World 18 April 2026
Cheap stuff that doesn’t suck, take 3

Cheap stuff that doesn’t suck, take 3

Digital World 18 April 2026
Dyson’s handheld fan is more powerful and louder than I expected

Dyson’s handheld fan is more powerful and louder than I expected

Digital World 18 April 2026
The AI apps are coming for your PC

The AI apps are coming for your PC

Digital World 18 April 2026
Should you stare into Sam Altman’s orb before your next date?

Should you stare into Sam Altman’s orb before your next date?

Digital World 17 April 2026
Top Articles
9 Longest-Lasting Nail Polishes, Tested by Top Manicurists

9 Longest-Lasting Nail Polishes, Tested by Top Manicurists

25 January 2026179 Views
Forbes ranked Canada’s top employers for 2026 and over 30 Quebec companies made the cut

Forbes ranked Canada’s top employers for 2026 and over 30 Quebec companies made the cut

22 January 2026100 Views
Canada’s best employers for 2026 were revealed and these are the top companies to work for

Canada’s best employers for 2026 were revealed and these are the top companies to work for

21 January 202698 Views
The Mother May I Story – Chickpea Edition

The Mother May I Story – Chickpea Edition

18 May 202497 Views
Demo
Don't Miss
“Giant” and the Weight of Words That Cannot Be Taken Back – front mezz junkies, Theater News
Reviews 19 April 2026

“Giant” and the Weight of Words That Cannot Be Taken Back – front mezz junkies, Theater News

John Lithgow in Broadway’s Giant. Photo by Joan Marcus. The Broadway Theatre Review: John Lithgow…

Safeguarding Your Website — BigScoots

3 essential Marvel Comics to read before Avengers: Doomsday

3 essential Marvel Comics to read before Avengers: Doomsday

10 fun things to do this week in and around Edmonton (April 20-24)

10 fun things to do this week in and around Edmonton (April 20-24)

About Us
About Us

Canadian Reviews is your one-stop website for the latest Canadian trends and things to do, follow us now to get the news that matters to you.

Facebook X (Twitter) Pinterest YouTube WhatsApp
Our Picks
19th Apr: Notting Hill (1999), 2hr 4m [PG-13] – Streaming Again (6.6/10)

19th Apr: Notting Hill (1999), 2hr 4m [PG-13] – Streaming Again (6.6/10)

Kicking off your Sunday shoes: Footloose at the Mayfield, a review, Theater News

Kicking off your Sunday shoes: Footloose at the Mayfield, a review, Theater News

All The Netflix Originals Leaving Netflix in April and May 2026

All The Netflix Originals Leaving Netflix in April and May 2026

Most Popular
Why You Should Consider Investing with IC Markets

Why You Should Consider Investing with IC Markets

28 April 202429 Views
OANDA Review – Low costs and no deposit requirements

OANDA Review – Low costs and no deposit requirements

28 April 2024362 Views
LearnToTrade: A Comprehensive Look at the Controversial Trading School

LearnToTrade: A Comprehensive Look at the Controversial Trading School

28 April 202476 Views
© 2026 ThemeSphere. Designed by ThemeSphere.
  • Privacy Policy
  • Terms of use
  • Advertise
  • Contact us

Type above and press Enter to search. Press Esc to cancel.