Malicious skills on claw hub and hugging face

Reddit r/openclaw News

Summary

Both Claw Hub and Hugging Face have been compromised, with 575 malicious skills uploaded; users are advised to exercise caution when using content from these platforms.

https://x.com/i/status/2052646258280432027 Evidently both sites have been hacked and there are 575 malicious skills on the sites. Be careful what you use from there.
Original Article

Similar Articles

Unit 42 found 5 malicious skills that passed ClawScan + VirusTotal

Reddit r/openclaw

Unit 42 discovered five malicious AI agent skills that evaded detection by ClawScan and VirusTotal, including referral-hijacking, crypto wallet draining, and a dropper hidden via size padding, demonstrating that signature scanning is ineffective against instruction-based threats.

Security for your OpenClaw agent skill before they run

Reddit r/openclaw

SecureSkill is a tool that performs 10-layer security analysis on OpenClaw agent skills before execution, detecting threats like credential harvesting, outbound calls, and shell scripts. It produces a signed audit report mapped to OWASP, MITRE, NIST, and EU AI Act standards.