This page contains press release content distributed by XPR Media. Members of the editorial and news staff of the USA TODAY Network were not involved in the creation of this content.

OpenClaw Security Audit Finds 41% of Skills Have Vulnerabilities

ClawSecure’s analysis of 2,890+ popular OpenClaw agent skills reveals 9,515 security findings, with 30.6% rated HIGH or CRITICAL severity.

ClawSecure found 41% of OpenClaw skills contain vulnerabilities. Users install agents on blind trust. We provide the data and monitoring they need.”
— J.D. Salbego, Founder of ClawSecure

SAN FRANCISCO, CA, UNITED STATES, March 11, 2026 /EINPresswire.com/ — 41% of popular OpenClaw skills contain at least one security vulnerability, according to the largest independent security audit of the OpenClaw ecosystem conducted by ClawSecure (https://www.clawsecure.ai). The audit analyzed 2,890+ popular OpenClaw agent skills drawn from the community-curated awesome-openclaw-skills list and the openclaw/skills repository, identifying 9,515 total security findings across the dataset. These represent the most widely installed agents in the OpenClaw ecosystem, which has surpassed 180,000 GitHub stars and attracts millions of weekly users since creator Peter Steinberger joined OpenAI in February 2026.
ClawSecure’s audit found that 30.6% of all audited skills contain vulnerabilities rated HIGH or CRITICAL in severity. ClawSecure’s analysis revealed that 99.3% of OpenClaw skills ship without a config.json permissions manifest, meaning users have no visibility into what system resources an agent will access before installation. Without a permissions manifest, an OpenClaw agent can request access to the file system, execute shell commands, read browser data, and make network calls to external servers with no user awareness. ClawSecure’s Watchtower monitoring system has tracked 661 code changes across registered skills, detecting cases where previously safe skills were modified post-installation to include suspicious behavior patterns.
The scope of findings spans every major vulnerability category that ClawSecure tracks. ClawSecure identified 539 skills exhibiting indicators consistent with the ClawHavoc malware campaign, a coordinated threat involving credential harvesting, command-and-control callbacks, and data exfiltration. ClawSecure also found widespread supply chain risks, including unpinned npm dependencies that allow compromised package versions to be silently pulled into a skill’s dependency tree. Credential exposure, unauthorized network calls, excessive permission requests, and ReDoS (Regular Expression Denial of Service) vulnerabilities were among the most common finding types across the dataset.
“The OpenClaw ecosystem is growing faster than its security infrastructure,” said J.D. Salbego, Founder of ClawSecure. “When nearly every skill ships without a permissions manifest and 41% contain vulnerabilities, users are installing agents on blind trust. ClawSecure exists to close that gap with real data and continuous monitoring, not just a one-time scan.”

ClawSecure’s proprietary 3-Layer Audit Protocol combines a behavioral analysis engine with 55+ threat patterns built specifically for OpenClaw, advanced static and behavioral analysis that traces execution paths across tool-calling chains, and full supply chain dependency scanning against known CVE databases. The platform detects the exploitation of what Palo Alto Networks (2026) calls the “Lethal Trifecta” of agentic AI risks: the combination of access to private data, exposure to untrusted content, and the ability to execute tools on the user’s behalf. ClawSecure’s Context-Aware Intelligence differentiates genuine threats from standard OpenClaw agent capabilities, reducing false positives that undermine developer trust in security tools. For example, ClawSecure’s audit of Peter Steinberger’s own flagship skill, peekaboo, scored it 95 out of 100, recognizing that its system-level capabilities are standard for a useful OpenClaw agent, while generic scanners flag it as suspicious.

ClawSecure’s Watchtower system provides continuous protection that one-time scanners cannot. Watchtower monitors all 2,890+ registered skills 24/7 using SHA-256 hash comparisons, automatically triggering a full re-audit through the 3-Layer Audit Protocol whenever a skill’s code is modified. This addresses the “sleeper agent” risk where a skill passes an initial review but is later updated to include malicious behavior. ClawSecure’s Watchtower has already detected 661 code changes across the registry, each triggering an immediate re-scan and updated security score.

ClawSecure has audited 2,890+ of the most popular OpenClaw skills and is the only platform providing free, public security audit reports with full OWASP ASI Top 10 coverage across all 10 categories. The platform achieves comprehensive coverage of the OWASP Agentic Security Initiative framework, which defines the industry standard for AI agent security risks including tool misuse, privilege escalation, goal hijacking, and supply chain compromise. ClawSecure is also the first OpenClaw security platform to publish formal NIST AI Risk Management Framework alignment documentation, available at the Trust Center (https://www.clawsecure.ai/trust).

The full dataset is available through ClawSecure’s public security registry (https://www.clawsecure.ai/registry), where developers can search, filter, and review audit results for any of the 2,890+ analyzed skills by security score, category, and risk level. ClawSecure’s Security Clearance API enables agent marketplaces and identity platforms to verify skill integrity programmatically before granting access, providing real-time SECURE, UNVERIFIED, or DENIED verdicts. The API is designed to complement identity verification platforms such as Moltbook, which provides creator identity and social reputation for its 2.2 million agents, while ClawSecure provides the code integrity verification that completes the trust stack. For users wondering how to check if an OpenClaw skill is safe before installing, ClawSecure’s scanner is free, requires no signup, and delivers results in under 30 seconds at https://www.clawsecure.ai.

Paul Bateman
ClawSecure, Inc
paul@clawsecure.ai
Visit us on social media:
LinkedIn
X

Legal Disclaimer:

EIN Presswire provides this news content “as is” without warranty of any kind. We do not accept any responsibility or liability
for the accuracy, content, images, videos, licenses, completeness, legality, or reliability of the information contained in this
article. If you have any complaints or copyright issues related to this article, kindly contact the author above.

Information contained on this page is provided by an independent third-party content provider. XPRMedia and this Site make no warranties or representations in connection therewith. If you are affiliated with this page and would like it removed please contact pressreleases@xpr.media

TuxCare To Present QCon London 2026 Session on Operating Open Source at Scale

TuxCare To Present QCon London 2026 Session on Operating Open Source at Scale

PALO ALTO, CA, UNITED STATES, March 12, 2026 /EINPresswire.com/ — TuxCare, a global innovator in securing open source,

March 12, 2026

Purdue University’s School of Health Sciences Invests in Alpha-E Fusion Device to Revolutionize Student Research

Purdue University’s School of Health Sciences Invests in Alpha-E Fusion Device to Revolutionize Student Research

WEST LAFAYETTE, IN, UNITED STATES, March 12, 2026 /EINPresswire.com/ — Alpha Ring, the global leader in micro-fusion

March 12, 2026

Influential Women Profiles: Ani Gamez: Tax Director at H&CO in Miami, Florida

Influential Women Profiles: Ani Gamez: Tax Director at H&CO in Miami, Florida

MIAMI, FL, UNITED STATES, March 12, 2026 /EINPresswire.com/ — Helping High-Net-Worth Clients Navigate Complex

March 12, 2026

Macxvideo AI V3.13 Adds Dedicated Audio-Only Recording and Improves Screen Capture Stability on macOS

Macxvideo AI V3.13 Adds Dedicated Audio-Only Recording and Improves Screen Capture Stability on macOS

Digiarty Software has released Macxvideo AI V3.13, adding an audio recorder and updating its screen recording module to

March 12, 2026

Best selling home cook releases her second book

Best selling home cook releases her second book

A passionate home cook whose recipes have led to millions of views online, is planning to release her second book. I

March 12, 2026

Influential Women Recognize Sharon M. Jacobs for 45 Years of Dedication to Student Success and Inclusive Education

Influential Women Recognize Sharon M. Jacobs for 45 Years of Dedication to Student Success and Inclusive Education

BARRE, VT, UNITED STATES, March 12, 2026 /EINPresswire.com/ — Veteran Vermont Educator and Mentor Continues Supporting

March 12, 2026

Chinese Neurosurgical Journal Study Develops a New Protocol for Determining Location of Paraclinoid Aneurysms

Chinese Neurosurgical Journal Study Develops a New Protocol for Determining Location of Paraclinoid Aneurysms

Researchers develop a modified high-resolution magnetic resonance imaging technique for determining the location of

March 12, 2026

Accelovant Unveils MPX‑EDGE: High‑Performance Edge AI/MIMO Controller for Next‑Gen Semiconductor Tools

Accelovant Unveils MPX‑EDGE: High‑Performance Edge AI/MIMO Controller for Next‑Gen Semiconductor Tools

Visit us at SEMI “Smarter Sensors, AI at the Edge in Semiconductor Manufacturing” and learn how it runs your

March 12, 2026

Standardizing the Economics of AI Discovery: Partnerize and Profound Establish Infrastructure for Zero-Click Commerce

Standardizing the Economics of AI Discovery: Partnerize and Profound Establish Infrastructure for Zero-Click Commerce

Collaboration connects AI discovery to actual revenue through intelligence, influence measurement, and verified payment

March 12, 2026

Premier Auto Protect Explains Rising Auto Extended Car Warranty Demand Amid Repair Cost Inflation

Premier Auto Protect Explains Rising Auto Extended Car Warranty Demand Amid Repair Cost Inflation

Premier Auto Protect explains how rising vehicle repair costs are leading more drivers to consider auto extended car

March 12, 2026

HAProxy Ranked #3 Best Web Hosting Software Product in G2’s 2026 Best Software Awards

HAProxy Ranked #3 Best Web Hosting Software Product in G2’s 2026 Best Software Awards

User-driven recognition highlights HAProxy’s leadership in Load Balancing, WAF, and DDoS Protection for scaling modern

March 12, 2026

a2b Fulfillment Achieves Milestone Safety Rating, Underscoring Operational Excellence

a2b Fulfillment Achieves Milestone Safety Rating, Underscoring Operational Excellence

GREENSBORO, GA, UNITED STATES, March 12, 2026 /EINPresswire.com/ — a2b Fulfillment, a leading provider of order

March 12, 2026

HMP Global’s Radiopharmaceutical Education Institute (RPEI) Aims to Advance Oncology Innovation

HMP Global’s Radiopharmaceutical Education Institute (RPEI) Aims to Advance Oncology Innovation

New, multidisciplinary platform delivers expert-driven education to support the evolving integration of

March 12, 2026

The Boxery Reports Dimensional Weight Is Reshaping E-Commerce Packaging—And Shipping Mailers Are the Fastest Fix

The Boxery Reports Dimensional Weight Is Reshaping E-Commerce Packaging—And Shipping Mailers Are the Fastest Fix

The Boxery explains how weight affects shipping costs and why many e-commerce businesses are switching to shipping

March 12, 2026

NDay, an NVIDIA Inception Member, Launches Self-Service GARAK AI LLM Red Teaming, Expanding Continuous Exploitability

NDay, an NVIDIA Inception Member, Launches Self-Service GARAK AI LLM Red Teaming, Expanding Continuous Exploitability

NDay, an NVIDIA Inception Member, Launches Self-Service GARAK AI Red Teaming, Expanding Its Continuous Exploitability

March 12, 2026

WhatsDash Rebrands as StatNexa, Launching a Unified Marketing Analytics Platform for Agencies

WhatsDash Rebrands as StatNexa, Launching a Unified Marketing Analytics Platform for Agencies

WhatsDash officially rebranded to StatNexa, introducing enhanced marketing analytics, advanced reporting dashboards,

March 12, 2026

Sober in Cyber and JackiesInSecurity Host Rockin’ Mocktails, An Alcohol-Free Networking Event for RSAC Attendees

Sober in Cyber and JackiesInSecurity Host Rockin’ Mocktails, An Alcohol-Free Networking Event for RSAC Attendees

Connect over mocktails, music, and creative activities at this inclusive alternative to traditional conference happy

March 12, 2026

Return Technologies Announces Renaud de Viel Castel as Co-Founder and Chief Executive Officer

Return Technologies Announces Renaud de Viel Castel as Co-Founder and Chief Executive Officer

Return Technologies named Renaud de Viel Castel Co-Founder & CEO. The company focuses on transparent, traceable

March 12, 2026

Moyae Launches Digital Retina Drawing Tool

Moyae Launches Digital Retina Drawing Tool

Moyae Launches Digital Retina Drawing Module, Replacing Paper Diagrams for Retina Specialists AUSTIN, TX, UNITED

March 12, 2026

AI Call Handling Technology Gains Adoption Among Home Service Businesses

AI Call Handling Technology Gains Adoption Among Home Service Businesses

Ringzy platform uses conversational AI voice agents to help contractors manage inbound calls SHELBY TOWNSHIP, MI,

March 12, 2026

GoML & Plumbata Launch AI Platform to Structure & Interpret Complex Union Agreements for Engineering & Construction

GoML & Plumbata Launch AI Platform to Structure & Interpret Complex Union Agreements for Engineering & Construction

In the construction industry, union agreements often exceed 600 pages. Plumbata turns these agreements into structured,

March 12, 2026

Florida State University Integrates RPM Platform to Train Next Generation of Researchers and Healthcare Professionals

Florida State University Integrates RPM Platform to Train Next Generation of Researchers and Healthcare Professionals

NEWARK, NJ, UNITED STATES, March 12, 2026 /EINPresswire.com/ — RPM Healthcare has been selected by Florida State

March 12, 2026

ANY.RUN Announces Integration with Tines to Accelerate SOC Response with Intelligent Workflows

ANY.RUN Announces Integration with Tines to Accelerate SOC Response with Intelligent Workflows

DUBAI, DUBAI, UNITED ARAB EMIRATES, March 12, 2026 /EINPresswire.com/ — ANY.RUN has launched a new integration with

March 12, 2026

TorchStone Global and Ontic announce strategic partnership

TorchStone Global and Ontic announce strategic partnership

Alliance designates TorchStone as Ontic’s preferred partner combining elite protective intelligence with

March 12, 2026

Sanpeggio’s Expands in Alabama with Grand Opening of its 7th Location in Hoover

Sanpeggio’s Expands in Alabama with Grand Opening of its 7th Location in Hoover

Sanpeggio’s opens its 7th Alabama location in Hoover, bringing handcrafted pizza and a welcoming neighborhood gathering

March 12, 2026

Overture Entertainment, Inc. Gives Way to Robtone, LLC

Overture Entertainment, Inc. Gives Way to Robtone, LLC

Multi-faceted entertainment company ends its 30-year run to form a streamline, more efficient entity. OEI was becoming

March 12, 2026

UAGC Launches Virtual Simulation Experiences to Prepare Future Early Childhood Educators

UAGC Launches Virtual Simulation Experiences to Prepare Future Early Childhood Educators

This project was designed to bridge the gap between theory and practice in online early childhood education.”—

March 12, 2026

Sphera Wins Five-Year Sole-Source Hazardous Materials Contract from the Defense Logistics Agency

Sphera Wins Five-Year Sole-Source Hazardous Materials Contract from the Defense Logistics Agency

Award reinforces Sphera’s leadership in chemical lifecycle management across the Department of War and NASA This award

March 12, 2026

SINQUA WALLS LEADS SXSW PANEL WITH ACCLAIMED PRODUCERS ON HOW ORIGINAL FILMS GET GREENLIT

SINQUA WALLS LEADS SXSW PANEL WITH ACCLAIMED PRODUCERS ON HOW ORIGINAL FILMS GET GREENLIT

Award-winning filmmakers and industry leaders convene at SXSW 2026 for a behind-the-scenes look at how original films

March 12, 2026

MethodSense Releases 2026 Regulatory Outlook for MedTech Industry

MethodSense Releases 2026 Regulatory Outlook for MedTech Industry

What regulatory shifts in AI, cybersecurity, digital submissions, and capital strategy mean for your success in 2026…

March 12, 2026

Magic Smiles for Kids Opens New Pediatric Dental Office in Bay Shore, New York

Magic Smiles for Kids Opens New Pediatric Dental Office in Bay Shore, New York

Magic Smiles for Kids provides children's dentistry focused on preventative care, early education & positive

March 12, 2026

Fresh Off His NAACP Image Awards Moment, Mali Music Heads to the DMV for One Night Only

Fresh Off His NAACP Image Awards Moment, Mali Music Heads to the DMV for One Night Only

The Grammy Award–winning artist returns to the East Coast for a special performance at The Birchmere in Alexandria,

March 12, 2026

QABA Expands Outreach in Thailand

QABA Expands Outreach in Thailand

Credentialing board visits local centers and hosts professional gathering to strengthen international ABA community The

March 12, 2026

Psynth Achieves HIPAA, PIPEDA, and GDPR Compliance: Independently Verified Across All Three Frameworks

Psynth Achieves HIPAA, PIPEDA, and GDPR Compliance: Independently Verified Across All Three Frameworks

AIS confirms no material gaps across all three privacy frameworks, making Psynth the only report writing platform for

March 12, 2026

Bainbridge Consulting Recognized in 2026 Vault Rankings and Featured in Forbes List of Top Consulting Firms (2016-2025)

Bainbridge Consulting Recognized in 2026 Vault Rankings and Featured in Forbes List of Top Consulting Firms (2016-2025)

Continued recognition reflects the firm's commitment to research-driven advisory and client outcomes These rankings

March 12, 2026

CadenceSEO Expands to Tennessee With Advanced SEO and Digital Marketing Services

CadenceSEO Expands to Tennessee With Advanced SEO and Digital Marketing Services

CadenceSEO brings tailored digital strategies, from Technical SEO Consulting to AI-driven visibility, to businesses

March 12, 2026

CIS Report Warns: AI Tools Can Aid Criminals in Planning Physical Attacks

CIS Report Warns: AI Tools Can Aid Criminals in Planning Physical Attacks

Our findings show GenAI is lowering the barrier of entry further than ever for people looking to plan real-world harm.

March 12, 2026

NYC interfaith Iftar: another powerful evening of unity

NYC interfaith Iftar: another powerful evening of unity

NEW YORK CITY, NY, UNITED STATES, March 12, 2026 /EINPresswire.com/ — The American Muslim & Multifaith Women’s

March 12, 2026

Technology B2B Sales Leader to Drive Profitable Growth for Chief Outsiders Clients

Technology B2B Sales Leader to Drive Profitable Growth for Chief Outsiders Clients

An expert in complex solution selling, Jim Wallace will deliver sustained revenue, margin, and customer satisfaction

March 12, 2026

Christopher Calabro Named to the LPL Ambassador Council

Christopher Calabro Named to the LPL Ambassador Council

ELMSFORD, NY, UNITED STATES, March 12, 2026 /EINPresswire.com/ — Christopher Calabro from CPC Wealth Management, based

March 12, 2026