---
title: "OpenClaw skills and AI agent security: why a malware scan isn't trust"
url: https://apyhub.com/blog/openclaw-skills-ai-agent-security
author: ApyHub
published: 2026-10-03T07:27:45Z
tags: [security, agents]
---

# OpenClaw skills and AI agent security: why a malware scan isn't trust

# OpenClaw skills and AI agent security: why a malware scan isn't trust

## Introduction

AI agent security is about controlling what your agent installs, what it calls, and what those tools do with your data. The biggest risk today is the tools themselves.

OpenClaw showed this in February. Its skill registry turned into a malware channel within weeks. The fix was malware scanning. Scanning helps, and it leaves the most important questions unanswered.

## What happened on ClawHub

ClawHub is OpenClaw's public skill registry. Anyone can upload to it.

[Koi Security audited 2,857 skills and found 341 malicious ones](https://thehackernews.com/2026/02/researchers-find-341-malicious-clawhub.html) (The Hacker News, February 2, 2026). They posed as crypto trackers and YouTube tools, then asked users to install a fake prerequisite that delivered a password stealer.

A skill is code that runs on your machine with your permissions. Installing one hands it your files and keys.

OpenClaw responded by [scanning every skill with VirusTotal](https://thehackernews.com/2026/02/openclaw-integrates-virustotal-scanning.html) and rescanning daily. Its own team called the scan "not a silver bullet."

The same report cited a Snyk finding: 283 skills, about 7% of the registry, leaked credentials in plaintext through the model's context and logs. None of them were malware. A scanner passes them.

## Why agents make it worse

A developer might pause at a strange package name. An agent installs what the task needs and moves on.

The numbers back this up. [Phoenix Security](https://phoenix.security/accelerating-supply-chain-attacks-npm-pypi-vsx-ai-enabled-2026/) (June 8, 2026) counted 4.5 times more malicious packages in the first half of 2026 than in all of 2025. AI agent skills were flagged as risky at 15.6%, more than double the rate of IDE extensions.

## What a scan tells your agent

| Before using a tool, your agent needs to know | Malware scan |
| --------------------------------------------- | ------------ |
| Does the code contain known malware?          | Yes          |
| Where is my data processed and stored?        | No           |
| How long is it kept?                          | No           |
| Who else receives it?                         | No           |
| Did the terms change since we approved it?    | No           |

A person builds trust slowly, through reputation and gut feeling. An agent has neither. It can only trust what it can read and check at the moment it acts.

## A safer default: call, don't install

When an agent calls a remote API, nothing new runs on your machine. That removes the attack ClawHavoc relied on.

It doesn't remove every risk. A remote service can still mishandle the data you send. So the agent needs to know how each service handles data before it calls it.

That is how [ApyHub](https://apyhub.com/) works. Every endpoint in the [catalog](https://apyhub.com/catalog) is available through ApyHub MCP, so agents can find and call APIs directly without a hand-written wrapper. The agent sees the cost before it commits. A search for EU VAT validation returns:

```json
{
  "service_display_name": "Validate EU VAT API",
  "method": "POST",
  "atoms": 50
}
```

Atoms are ApyHub's per-call unit. They reflect the compute work behind each request.

Each service also carries machine-readable attributes on data handling, retention, compliance and third parties, aligned with GDPR, SOC 2, ISO 27001 and OWASP API guidelines. You set your organization's policy once, and ApyHub matches every service against it. Your agent reads the facts and your policy decides.

[**Explore the catalog →**](https://apyhub.com/catalog)

## Four rules for your agent

1. **Prefer calling over installing** when a task doesn't need local access.
2. **Pin skills and turn off auto-updates.** A clean skill can turn malicious in its next version.
3. **Keep credentials out of the agent's context.** Leaks happen without any malware.
4. **Require data-handling facts for every tool.** If a tool can't tell you where your data goes, treat it as unknown.

## Conclusion

ClawHub showed how fast an open registry becomes an attack channel once agents use it. Scanning closes the obvious gap. It can't tell your agent where your data goes or whether anything changed since approval. Those answers have to be machine-readable, or the agent is acting on hope.

[**Try ApyHub MCP free →**](https://apyhub.com/)

## FAQ

**What happened with OpenClaw's ClawHub?** In February 2026, researchers found 341 malicious skills out of 2,857 on ClawHub. Most installed a password stealer through a fake prerequisite step.

**Are OpenClaw skills safe now?** ClawHub scans every upload and rescans daily, which catches known malware. OpenClaw says hidden prompt injection can still get through, so review skills before installing.

**What's the difference between a skill and an API call?** A skill runs on your machine with your permissions. An API call sends a request to a remote service, so no new code runs locally.

**Does MCP make agents secure?** MCP standardizes how agents find and call tools. Security depends on what the server exposes and what the agent is allowed to call.

**How can I test an API before my agent calls it?** Use the playground on the API's ApyHub page, [Voiden](https://voiden.md/) (an open-source API client that keeps requests as Markdown in your repo), or curl.

**Do I need to write tool definitions for ApyHub APIs?** No. Every endpoint is available through ApyHub MCP, so your agent can search, read the schema and call it directly.

## About ApyHub

[ApyHub](https://apyhub.com/) is a curated API catalog and trusted operational layer for developers and AI agents. Teams access [over 1,500 endpoints and capabilities, with more added continuously](https://apyhub.com/catalog), through a single subscription measured in atoms, a per-call unit that reflects the actual compute work of each request. Every service carries machine-readable certification aligned with GDPR, SOC 2 and ISO 27001, and every endpoint is MCP-ready by default, so AI agents can discover and call APIs without custom wrappers. ApyHub is headquartered in Amsterdam, with offices in the Netherlands, Greece and India, and serves 65,000+ monthly developer workspaces. The free tier needs no credit card. API providers can publish to the catalog through the [provider program](https://apyhub.com/api-provider).
