apyhub
Cover illustration for OpenClaw skills and AI agent security: why a malware scan isn't trust
Security · Agents

OpenClaw skills and AI agent security: why a malware scan isn't trust

OpenClaw skills and AI agent security: why a malware scan isn't trust

01Introduction

AI agent security is about controlling what your agent installs, what it calls, and what those tools do with your data. The biggest risk today is the tools themselves.

OpenClaw showed this in February. Its skill registry turned into a malware channel within weeks. The fix was malware scanning. Scanning helps, and it leaves the most important questions unanswered.

02What happened on ClawHub

ClawHub is OpenClaw's public skill registry. Anyone can upload to it.

Koi Security audited 2,857 skills and found 341 malicious ones (The Hacker News, February 2, 2026). They posed as crypto trackers and YouTube tools, then asked users to install a fake prerequisite that delivered a password stealer.

A skill is code that runs on your machine with your permissions. Installing one hands it your files and keys.

OpenClaw responded by scanning every skill with VirusTotal and rescanning daily. Its own team called the scan "not a silver bullet."

The same report cited a Snyk finding: 283 skills, about 7% of the registry, leaked credentials in plaintext through the model's context and logs. None of them were malware. A scanner passes them.

03Why agents make it worse

A developer might pause at a strange package name. An agent installs what the task needs and moves on.

The numbers back this up. Phoenix Security (June 8, 2026) counted 4.5 times more malicious packages in the first half of 2026 than in all of 2025. AI agent skills were flagged as risky at 15.6%, more than double the rate of IDE extensions.

04What a scan tells your agent

Before using a tool, your agent needs to knowMalware scan
Does the code contain known malware?Yes
Where is my data processed and stored?No
How long is it kept?No
Who else receives it?No
Did the terms change since we approved it?No

A person builds trust slowly, through reputation and gut feeling. An agent has neither. It can only trust what it can read and check at the moment it acts.

05A safer default: call, don't install

When an agent calls a remote API, nothing new runs on your machine. That removes the attack ClawHavoc relied on.

It doesn't remove every risk. A remote service can still mishandle the data you send. So the agent needs to know how each service handles data before it calls it.

That is how ApyHub works. Every endpoint in the catalog is available through ApyHub MCP, so agents can find and call APIs directly without a hand-written wrapper. The agent sees the cost before it commits. A search for EU VAT validation returns:

· json
{
  "service_display_name": "Validate EU VAT API",
  "method": "POST",
  "atoms": 50
}

Atoms are ApyHub's per-call unit. They reflect the compute work behind each request.

Each service also carries machine-readable attributes on data handling, retention, compliance and third parties, aligned with GDPR, SOC 2, ISO 27001 and OWASP API guidelines. You set your organization's policy once, and ApyHub matches every service against it. Your agent reads the facts and your policy decides.

Explore the catalog →

06Four rules for your agent

  1. Prefer calling over installing when a task doesn't need local access.
  2. Pin skills and turn off auto-updates. A clean skill can turn malicious in its next version.
  3. Keep credentials out of the agent's context. Leaks happen without any malware.
  4. Require data-handling facts for every tool. If a tool can't tell you where your data goes, treat it as unknown.

07Conclusion

ClawHub showed how fast an open registry becomes an attack channel once agents use it. Scanning closes the obvious gap. It can't tell your agent where your data goes or whether anything changed since approval. Those answers have to be machine-readable, or the agent is acting on hope.

Try ApyHub MCP free →

08FAQ

What happened with OpenClaw's ClawHub? In February 2026, researchers found 341 malicious skills out of 2,857 on ClawHub. Most installed a password stealer through a fake prerequisite step.

Are OpenClaw skills safe now? ClawHub scans every upload and rescans daily, which catches known malware. OpenClaw says hidden prompt injection can still get through, so review skills before installing.

What's the difference between a skill and an API call? A skill runs on your machine with your permissions. An API call sends a request to a remote service, so no new code runs locally.

Does MCP make agents secure? MCP standardizes how agents find and call tools. Security depends on what the server exposes and what the agent is allowed to call.

How can I test an API before my agent calls it? Use the playground on the API's ApyHub page, Voiden (an open-source API client that keeps requests as Markdown in your repo), or curl.

Do I need to write tool definitions for ApyHub APIs? No. Every endpoint is available through ApyHub MCP, so your agent can search, read the schema and call it directly.

09About ApyHub

ApyHub is a curated API catalog and trusted operational layer for developers and AI agents. Teams access over 1,500 endpoints and capabilities, with more added continuously, through a single subscription measured in atoms, a per-call unit that reflects the actual compute work of each request. Every service carries machine-readable certification aligned with GDPR, SOC 2 and ISO 27001, and every endpoint is MCP-ready by default, so AI agents can discover and call APIs without custom wrappers. ApyHub is headquartered in Amsterdam, with offices in the Netherlands, Greece and India, and serves 65,000+ monthly developer workspaces. The free tier needs no credit card. API providers can publish to the catalog through the provider program.