The content on this page was provided by an independent third party and syndicated by XPR Media. Members of the editorial and news staff of the USA TODAY Network were not involved in the creation of this content.

OpenClaw Security Audit Finds 41% of Skills Have Vulnerabilities

ClawSecure’s analysis of 2,890+ popular OpenClaw agent skills reveals 9,515 security findings, with 30.6% rated HIGH or CRITICAL severity.

ClawSecure found 41% of OpenClaw skills contain vulnerabilities. Users install agents on blind trust. We provide the data and monitoring they need.”
— J.D. Salbego, Founder of ClawSecure

SAN FRANCISCO, CA, UNITED STATES, March 11, 2026 /EINPresswire.com/ — 41% of popular OpenClaw skills contain at least one security vulnerability, according to the largest independent security audit of the OpenClaw ecosystem conducted by ClawSecure (https://www.clawsecure.ai). The audit analyzed 2,890+ popular OpenClaw agent skills drawn from the community-curated awesome-openclaw-skills list and the openclaw/skills repository, identifying 9,515 total security findings across the dataset. These represent the most widely installed agents in the OpenClaw ecosystem, which has surpassed 180,000 GitHub stars and attracts millions of weekly users since creator Peter Steinberger joined OpenAI in February 2026.
ClawSecure’s audit found that 30.6% of all audited skills contain vulnerabilities rated HIGH or CRITICAL in severity. ClawSecure’s analysis revealed that 99.3% of OpenClaw skills ship without a config.json permissions manifest, meaning users have no visibility into what system resources an agent will access before installation. Without a permissions manifest, an OpenClaw agent can request access to the file system, execute shell commands, read browser data, and make network calls to external servers with no user awareness. ClawSecure’s Watchtower monitoring system has tracked 661 code changes across registered skills, detecting cases where previously safe skills were modified post-installation to include suspicious behavior patterns.
The scope of findings spans every major vulnerability category that ClawSecure tracks. ClawSecure identified 539 skills exhibiting indicators consistent with the ClawHavoc malware campaign, a coordinated threat involving credential harvesting, command-and-control callbacks, and data exfiltration. ClawSecure also found widespread supply chain risks, including unpinned npm dependencies that allow compromised package versions to be silently pulled into a skill’s dependency tree. Credential exposure, unauthorized network calls, excessive permission requests, and ReDoS (Regular Expression Denial of Service) vulnerabilities were among the most common finding types across the dataset.
“The OpenClaw ecosystem is growing faster than its security infrastructure,” said J.D. Salbego, Founder of ClawSecure. “When nearly every skill ships without a permissions manifest and 41% contain vulnerabilities, users are installing agents on blind trust. ClawSecure exists to close that gap with real data and continuous monitoring, not just a one-time scan.”

ClawSecure’s proprietary 3-Layer Audit Protocol combines a behavioral analysis engine with 55+ threat patterns built specifically for OpenClaw, advanced static and behavioral analysis that traces execution paths across tool-calling chains, and full supply chain dependency scanning against known CVE databases. The platform detects the exploitation of what Palo Alto Networks (2026) calls the “Lethal Trifecta” of agentic AI risks: the combination of access to private data, exposure to untrusted content, and the ability to execute tools on the user’s behalf. ClawSecure’s Context-Aware Intelligence differentiates genuine threats from standard OpenClaw agent capabilities, reducing false positives that undermine developer trust in security tools. For example, ClawSecure’s audit of Peter Steinberger’s own flagship skill, peekaboo, scored it 95 out of 100, recognizing that its system-level capabilities are standard for a useful OpenClaw agent, while generic scanners flag it as suspicious.

ClawSecure’s Watchtower system provides continuous protection that one-time scanners cannot. Watchtower monitors all 2,890+ registered skills 24/7 using SHA-256 hash comparisons, automatically triggering a full re-audit through the 3-Layer Audit Protocol whenever a skill’s code is modified. This addresses the “sleeper agent” risk where a skill passes an initial review but is later updated to include malicious behavior. ClawSecure’s Watchtower has already detected 661 code changes across the registry, each triggering an immediate re-scan and updated security score.

ClawSecure has audited 2,890+ of the most popular OpenClaw skills and is the only platform providing free, public security audit reports with full OWASP ASI Top 10 coverage across all 10 categories. The platform achieves comprehensive coverage of the OWASP Agentic Security Initiative framework, which defines the industry standard for AI agent security risks including tool misuse, privilege escalation, goal hijacking, and supply chain compromise. ClawSecure is also the first OpenClaw security platform to publish formal NIST AI Risk Management Framework alignment documentation, available at the Trust Center (https://www.clawsecure.ai/trust).

The full dataset is available through ClawSecure’s public security registry (https://www.clawsecure.ai/registry), where developers can search, filter, and review audit results for any of the 2,890+ analyzed skills by security score, category, and risk level. ClawSecure’s Security Clearance API enables agent marketplaces and identity platforms to verify skill integrity programmatically before granting access, providing real-time SECURE, UNVERIFIED, or DENIED verdicts. The API is designed to complement identity verification platforms such as Moltbook, which provides creator identity and social reputation for its 2.2 million agents, while ClawSecure provides the code integrity verification that completes the trust stack. For users wondering how to check if an OpenClaw skill is safe before installing, ClawSecure’s scanner is free, requires no signup, and delivers results in under 30 seconds at https://www.clawsecure.ai.

Paul Bateman
ClawSecure, Inc
paul@clawsecure.ai
Visit us on social media:
LinkedIn
X

Legal Disclaimer:

EIN Presswire provides this news content “as is” without warranty of any kind. We do not accept any responsibility or liability
for the accuracy, content, images, videos, licenses, completeness, legality, or reliability of the information contained in this
article. If you have any complaints or copyright issues related to this article, kindly contact the author above.

Information contained on this page is provided by an independent third-party content provider. XPRMedia and this Site make no warranties or representations in connection therewith. If you are affiliated with this page and would like it removed please contact pressreleases@xpr.media

Researchers Break Decades-old Bottleneck in Chemotherapy Drug Manufacturing

Researchers Break Decades-old Bottleneck in Chemotherapy Drug Manufacturing

New method produces 180% more doxorubicin than current industrial standards We have harnessed rational strain

March 13, 2026

Gripping Documentary #WhileBlack explores the Human Cost of Viral Citizen Journalism as it premieres at SXSW 2026

Gripping Documentary #WhileBlack explores the Human Cost of Viral Citizen Journalism as it premieres at SXSW 2026

#WhileBlack is a visually striking documentary that examines how citizen journalism is being transformed, where memory,

March 13, 2026

Genesis Systems CEO Shannon Stuckenberg Named to Inc. Female Founders 500 List as WaterCube® Tech Expands Globally

Genesis Systems CEO Shannon Stuckenberg Named to Inc. Female Founders 500 List as WaterCube® Tech Expands Globally

Genesis Systems Leadership Gains Global Recognition as WaterCube® Passes the Department of Defense (DoD) Highest Water

March 13, 2026

Premier Auto Protect Highlights Car Warranty Extended Demand as ADAS Repair Costs Rise

Premier Auto Protect Highlights Car Warranty Extended Demand as ADAS Repair Costs Rise

Premier Auto Protect reports growing interest in extended car warranty coverage as ADAS technology increases repair

March 13, 2026

The Boxery Expands Focus on Supply Chain Resilience for Corrugated Boxes to Help Businesses Avoid Stockouts

The Boxery Expands Focus on Supply Chain Resilience for Corrugated Boxes to Help Businesses Avoid Stockouts

The Boxery expands its focus on supply chain resilience for corrugated boxes, helping businesses maintain steady

March 13, 2026

Industrial Construction Boom Driving Interest in Modular Workforce Housing Solutions

Industrial Construction Boom Driving Interest in Modular Workforce Housing Solutions

Developers exploring flexible housing options as large infrastructure projects expand across the United States As major

March 13, 2026

American Painting Specialists Launches Modern Website for Denver Clients

American Painting Specialists Launches Modern Website for Denver Clients

DENVER, CO, UNITED STATES, March 13, 2026 /EINPresswire.com/ — American Painting Specialists has officially launched

March 13, 2026

China-Based Manufacturers for EN 13432 and ASTM D6400 Certified Compostable Food Containers

China-Based Manufacturers for EN 13432 and ASTM D6400 Certified Compostable Food Containers

FUZHOU, FUJIAN, CHINA, March 13, 2026 /EINPresswire.com/ — Choosing a Certified Partner for Sustainable Packaging Are

March 13, 2026

Optimizing Supply Chains with Custom Shipping Box Solutions from China

Optimizing Supply Chains with Custom Shipping Box Solutions from China

FUZHOU, FUJIAN, CHINA, March 13, 2026 /EINPresswire.com/ — Packaging plays a critical role in global supply chain

March 13, 2026

A Historic First: Single Women Overtake Men in Purchasing Power and Market Share as First-Time Homebuyers

A Historic First: Single Women Overtake Men in Purchasing Power and Market Share as First-Time Homebuyers

NAEBA Highlights A Historic First: Single Women Overtake Men in Purchasing Power and Market Share as First-Time

March 13, 2026

Chinese Neurosurgical Journal Reports Faster Robot-Assisted Brain Angiography

Chinese Neurosurgical Journal Reports Faster Robot-Assisted Brain Angiography

First real-world validation of China’s YDHB-NS01 shows 100% success, shorter procedures than manual angiography, and no

March 13, 2026

French Quarter Festival Returns April 16–19 with Free Music, Local Cuisine, and Four Days of Celebration in New Orleans

French Quarter Festival Returns April 16–19 with Free Music, Local Cuisine, and Four Days of Celebration in New Orleans

Beloved annual festival highlights local musicians, iconic Louisiana food vendors, and the culture of the historic

March 13, 2026

Eso Soccer and Bridgeview Foundation to Host ‘2026 Freedom To Play’ Post-Hurricane Relief Event in Jamaica

Eso Soccer and Bridgeview Foundation to Host ‘2026 Freedom To Play’ Post-Hurricane Relief Event in Jamaica

"Uniting Communities Through the Global Game" We are looking forward to capturing the excitement that the World Cup

March 13, 2026

New UK Border Rules Mean British Dual Citizens May Be Denied Boarding Without a British Passport

New UK Border Rules Mean British Dual Citizens May Be Denied Boarding Without a British Passport

New UK ETA travel rules mean British dual citizens must use a British passport or proof of right of abode. Learn what

March 13, 2026

John Kerry to join the Ocean Stewardship Initiative (OSI) as a Champion

John Kerry to join the Ocean Stewardship Initiative (OSI) as a Champion

The Sustainable Markets Initiative, founded by His Majesty King Charles III, announces John Kerry as Champion for Ocean

March 13, 2026

Sturlite Announces Successful SAP S/4HANA EWM Public Cloud Implementation & RF Integration with Fingent

Sturlite Announces Successful SAP S/4HANA EWM Public Cloud Implementation & RF Integration with Fingent

The successful implementation of SAP S/4HANA EWM Public Cloud & RF Integration reflects strong collaboration

March 13, 2026

VGS Portfolio Supercharges Viking SupplyNet’s Unique, Vertically Integrated Model with Premium Piping Connections

VGS Portfolio Supercharges Viking SupplyNet’s Unique, Vertically Integrated Model with Premium Piping Connections

Viking SupplyNet expands its portfolio with VGS, a premium lineup of piping connections designed to streamline

March 13, 2026

Inside the 2026 Hollywood Swag Bag Celebrating Oscar Weekend Nominees and Casting Directors

Inside the 2026 Hollywood Swag Bag Celebrating Oscar Weekend Nominees and Casting Directors

Luxury gift basket highlights innovative brands and celebrates the first year casting directors are honored during

March 13, 2026

Jarzynski equality in the context of superconducting optical cavities

Jarzynski equality in the context of superconducting optical cavities

FAYETTEVILLE, GA, UNITED STATES, March 13, 2026 /EINPresswire.com/ — This article investigates the classical limit of

March 13, 2026

Buyer’s Guide to Easy-Clean Anti-Fingerprint HPL Sheets for Modern Cabinetry Applications

Buyer’s Guide to Easy-Clean Anti-Fingerprint HPL Sheets for Modern Cabinetry Applications

CHANGZHOU, JIANGSU, CHINA, March 13, 2026 /EINPresswire.com/ — As cabinetry design trends move toward matte finishes,

March 13, 2026

New Survey Shows How AI is Transforming the American Workplace in 2026

New Survey Shows How AI is Transforming the American Workplace in 2026

Novorésumé’s latest study reveals trends in AI reliance, AI sentiment, and generational differences This is what

March 13, 2026

How to Choose a Reliable High Pressure Decorative Laminates Supplier in China

How to Choose a Reliable High Pressure Decorative Laminates Supplier in China

CHANGZHOU, JIANGSU, CHINA, March 13, 2026 /EINPresswire.com/ — As global construction and furniture markets continue

March 13, 2026

Nebo Launches Marketing Predictive App with up to 99% Accuracy

Nebo Launches Marketing Predictive App with up to 99% Accuracy

The model has proven to be over 97% accurate, and for some clients it has proven to be over 99% accurate Ironically,

March 13, 2026

Compliant, Safe, Efficient: ATEX Vacuum Solution for Technical and Medical Gases

Compliant, Safe, Efficient: ATEX Vacuum Solution for Technical and Medical Gases

Industrial operations are facing increasing challenges from new regulatory requirements – especially when dealing with

March 13, 2026

CredibleLaw.com Launches National Merchant Cash Advance Research Hub

CredibleLaw.com Launches National Merchant Cash Advance Research Hub

New research hub analyzes MCA industry growth, litigation trends, and state laws to help businesses understand the

March 13, 2026

China Leading UV LED Curing Solution Provider at RadTech UV+EB Technology Expo & Conference (USA)

China Leading UV LED Curing Solution Provider at RadTech UV+EB Technology Expo & Conference (USA)

ZHUHAI, GUANGDONG, CHINA, March 13, 2026 /EINPresswire.com/ — The intersection of global manufacturing and sustainable

March 13, 2026

Thruvision secures further U.S. aviation contract award from Greater Orlando Aviation Authority

Thruvision secures further U.S. aviation contract award from Greater Orlando Aviation Authority

Greater Orlando Aviation Authority has placed an order for Thruvision systems to support aviation worker screening

March 13, 2026

Chinese Top 3 Solar Street Light Manufacturers in 2026 Leading the Global Solar Lighting Industry with Innovation

Chinese Top 3 Solar Street Light Manufacturers in 2026 Leading the Global Solar Lighting Industry with Innovation

Driving the future of renewable outdoor lighting through cutting-edge solar technology, intelligent control systems,

March 13, 2026

The Space Launch Services Market is projected to attain a value of US $24.42 billion by 2030

The Space Launch Services Market is projected to attain a value of US $24.42 billion by 2030

The Business Research Company's The Space Launch Services Market is projected to attain a value of US $24.42 billion by

March 13, 2026

conga-TCRP1 combines high performance with maximum scalability and design flexibility

conga-TCRP1 combines high performance with maximum scalability and design flexibility

Scalable Edge Performance for Demanding Applications SAN DIEGO, CA, UNITED STATES, March 13, 2026 /EINPresswire.com/ —

March 13, 2026

conga-HPC/cBLS accelerates demanding edge designs

conga-HPC/cBLS accelerates demanding edge designs

More consistent power for COM-HPC client platforms SAN DIEGO, CA, UNITED STATES, March 13, 2026 /EINPresswire.com/ —

March 13, 2026

AAA Organized Plumbing Expands Professional Plumbing Services to Napa Valley Communities

AAA Organized Plumbing Expands Professional Plumbing Services to Napa Valley Communities

Ukiah plumbing company brings trusted residential and commercial expertise to Napa County, offering homeowners and

March 13, 2026

5 Essential Features to Look for in a China Trail Run Shoes Manufacturer for Professional Athletes

5 Essential Features to Look for in a China Trail Run Shoes Manufacturer for Professional Athletes

SHENZHEN, GUANGDONG, CHINA, March 13, 2026 /EINPresswire.com/ — The global landscape of outdoor sports has undergone a

March 13, 2026

TRWD Announces Entry into $10B Growth Sector

TRWD Announces Entry into $10B Growth Sector

Company Announced Plans To Become One of Only Two Publicly Traded Entities in a $10 Billion Industry; Execution Begins

March 13, 2026

congatec and Kontron partner on embedded computing solutions

congatec and Kontron partner on embedded computing solutions

congatec launches aReady.YOURS Partner Program for market-specific system solutions SAN DIEGO, CA, UNITED STATES, March

March 13, 2026

Cure All Plumbing Reinforces Commitment to Professional Standards and Community Support in Arizona

Cure All Plumbing Reinforces Commitment to Professional Standards and Community Support in Arizona

GILBERT, AZ, UNITED STATES, March 13, 2026 /EINPresswire.com/ — After more than two decades in the plumbing industry,

March 13, 2026

aReady.YOURS from congatec for fast and reliable (full) custom embedded computing designs

aReady.YOURS from congatec for fast and reliable (full) custom embedded computing designs

congatec centralizes customization design and software integration services in new Customer Application Center and

March 13, 2026

PEL Learning Expands Academic & Franchise Opportunities in California

PEL Learning Expands Academic & Franchise Opportunities in California

PEL Learning Centers expands in California with mastery-based Math & ELA tutoring using Singapore Math and Spalding

March 13, 2026

Industry Recognition for Excellence: RakSmart Honored with HostingSeekers ‘2026 Fastest Growing Hosting Brand’ Award

Industry Recognition for Excellence: RakSmart Honored with HostingSeekers ‘2026 Fastest Growing Hosting Brand’ Award

RakSmart wins HostingSeekers’s 2026 Fastest Growing Hosting Brand, known for innovation, 99.9% uptime, fast support

March 13, 2026

Beast Games Winner Jeff Allen Doubles Down on Mission to Fund Cure for Rare Disease Affecting His Son

Beast Games Winner Jeff Allen Doubles Down on Mission to Fund Cure for Rare Disease Affecting His Son

Allen completes second Ruck4Rare & pledges $1 million to ACD's Race for a Cure Every mile I ruck, every fundraiser,

March 13, 2026