Gallery

Contacts

405 W. Greenlawn Ave Lansing, Michigan 48910

contact@techjacksolutions.com

+1-616-320-4064

Attackers distributed over 800 malicious packages through ClawHub, the third-party skills marketplace for the OpenClaw AI agent platform, bypassing platform security vetting and delivering infostealers directly into AI agent pipelines. Snyk’s ToxicSkills research identified 1,467 malicious payloads and prompt injection vulnerabilities in 36% of analyzed skills; a separate Silverfort disclosure revealed a ranking manipulation vulnerability that surfaced malicious packages as top results, increasing installation volume. Organizations running OpenClaw with third-party ClawHub skills face credential theft, session token compromise, and potential lateral movement into any downstream system the agent is authorized to access.

Author

Tech Jacks Solutions