OpenClaw has a process of flagging skills as potentially malicious. AI developers may still be exposed by malicious skills, currently only handled by an imperfectOpenClaw has a process of flagging skills as potentially malicious. AI developers may still be exposed by malicious skills, currently only handled by an imperfect

Researchers warn OpenClaw skill scanning fails to prevent malicious AI agent plugins

2026/03/17 02:21
3 min read
For feedback or concerns regarding this content, please contact us at crypto.news@mexc.com

Recent research shows that OpenClaw’s skill-scanning system is not a secure boundary. Posting third-party skills remains a problem for AI agent creation and usage. 

OpenClaw skills still pose security threats, and the recent skill-scanning system is not a secure boundary, according to recent security expert research. Skill scanning has been proposed as a gateway for skill publishers, aiming to intercept potentially malicious data payloads or malicious elements of the skill itself. 

As Cryptopolitan reported, third-party services have already posed security risks, and AI agent adoption is accelerating and worsening the problem. 

OpenClaw allows the user to create agents and run them on a local machine or a server. However, skills immediately alongside OpenClaw, and may inherit the same access to resources and tools. Since some skills involve sensitive tasks such as wallet access or on-chain interactions, the skill sets posted by third parties remain a risk. 

How does OpenClaw check skills for malicious intent? 

Recent research showed Clawhub uses VirusTotal, as well as OpenClaw’s internal moderation system. The results of those checks classify the skills and set up user warnings during installation. 

This system is still imperfect and may deem harmless or even potentially harmful skills. A problem arises when VirusTotal flags the skill as suspicious, and OpenClaw as benign. The user is shown a warning, and may still confirm the skill installation. Skills fully flagged as malicious are not allowed for downloads. 

OpenClaw also offers sandboxing and runtime controls, but these are optional and do not constitute a hard default boundary for third-party skills. OpenClaw leaves Docker-based sandboxing optional, and some tools remain available with it switched off. 

Users also choose the direct path because sandbox environments can be difficult to deploy, and some skills break down. This also means that the platform depends on reviews and warnings, a system that is not directly protective when running agent skills. 

Can OpenClaw catch malicious skills? 

OpenClaw has already implemented some security measures, including checks for behaviors specifically linked to catch code that can read secrets and send them out. This approach is used in traditional security to detect suspicious processes, requests, and other behaviors. 

AI agent skills are harder to scan because the inputs involve both code and natural-language instructions, as well as runtime behavior. Traditional security may have blind spots for agentic behaviors.

The next layer is to use AI scanning to catch more risky behaviors that weren’t caught by a static search or the usual regular expression approach. AI agents can give a glimpse into the internal consistency of skills, while not being exhaustive of the potential for exploits. They search for the most obvious exploitable code or general inconsistencies. 

Researchers noted the OpenClaw checks and moderation system was fast to approve skills, while VirusTotal sometimes took days to flag the addition. It was also possible to add exploits to already approved skills. This meant that the OpenClaw process could proclaim skills were benign when they could contain unexpected behaviors. 

For AI agent developers, researchers recommend sandboxing or using tools to prevent skills from running, even if they are flagged as benign. The researchers called for skill platforms to assume that normal-looking skills may hide exploits and to avoid using them in high-value environments, potentially granting access to crypto wallets or other sensitive information.

Your bank is using your money. You’re getting the scraps. Watch our free video on becoming your own bank

Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact crypto.news@mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

Polygon Tops RWA Rankings With $1.1B in Tokenized Assets

Polygon Tops RWA Rankings With $1.1B in Tokenized Assets

The post Polygon Tops RWA Rankings With $1.1B in Tokenized Assets appeared on BitcoinEthereumNews.com. Key Notes A new report from Dune and RWA.xyz highlights Polygon’s role in the growing RWA sector. Polygon PoS currently holds $1.13 billion in RWA Total Value Locked (TVL) across 269 assets. The network holds a 62% market share of tokenized global bonds, driven by European money market funds. The Polygon POL $0.25 24h volatility: 1.4% Market cap: $2.64 B Vol. 24h: $106.17 M network is securing a significant position in the rapidly growing tokenization space, now holding over $1.13 billion in total value locked (TVL) from Real World Assets (RWAs). This development comes as the network continues to evolve, recently deploying its major “Rio” upgrade on the Amoy testnet to enhance future scaling capabilities. This information comes from a new joint report on the state of the RWA market published on Sept. 17 by blockchain analytics firm Dune and data platform RWA.xyz. The focus on RWAs is intensifying across the industry, coinciding with events like the ongoing Real-World Asset Summit in New York. Sandeep Nailwal, CEO of the Polygon Foundation, highlighted the findings via a post on X, noting that the TVL is spread across 269 assets and 2,900 holders on the Polygon PoS chain. The Dune and https://t.co/W6WSFlHoQF report on RWA is out and it shows that RWA is happening on Polygon. Here are a few highlights: – Leading in Global Bonds: Polygon holds 62% share of tokenized global bonds (driven by Spiko’s euro MMF and Cashlink euro issues) – Spiko U.S.… — Sandeep | CEO, Polygon Foundation (※,※) (@sandeepnailwal) September 17, 2025 Key Trends From the 2025 RWA Report The joint publication, titled “RWA REPORT 2025,” offers a comprehensive look into the tokenized asset landscape, which it states has grown 224% since the start of 2024. The report identifies several key trends driving this expansion. According to…
Share
BitcoinEthereumNews2025/09/18 00:40
US Dollar pulls back as markets assess Iran; Fed, ECB ahead

US Dollar pulls back as markets assess Iran; Fed, ECB ahead

The post US Dollar pulls back as markets assess Iran; Fed, ECB ahead appeared on BitcoinEthereumNews.com. Here is what you need to know for Tuesday, March 17: The
Share
BitcoinEthereumNews2026/03/17 03:29
Vitalik Buterin Reveals Ethereum’s Long-Term Focus on Quantum Resistance

Vitalik Buterin Reveals Ethereum’s Long-Term Focus on Quantum Resistance

TLDR Ethereum focuses on quantum resistance to secure the blockchain’s future. Vitalik Buterin outlines Ethereum’s long-term development with security goals. Ethereum aims for improved transaction efficiency and layer-2 scalability. Ethereum maintains a strong market position with price stability above $4,000. Vitalik Buterin, the co-founder of Ethereum, has shared insights into the blockchain’s long-term development. During [...] The post Vitalik Buterin Reveals Ethereum’s Long-Term Focus on Quantum Resistance appeared first on CoinCentral.
Share
Coincentral2025/09/18 00:31