This page contains press release content distributed by XPR Media. Members of the editorial and news staff of the USA TODAY Network were not involved in the creation of this content.

OpenClaw Security Audit Finds 41% of Skills Have Vulnerabilities

ClawSecure’s analysis of 2,890+ popular OpenClaw agent skills reveals 9,515 security findings, with 30.6% rated HIGH or CRITICAL severity.

ClawSecure found 41% of OpenClaw skills contain vulnerabilities. Users install agents on blind trust. We provide the data and monitoring they need.”
— J.D. Salbego, Founder of ClawSecure

SAN FRANCISCO, CA, UNITED STATES, March 11, 2026 /EINPresswire.com/ — 41% of popular OpenClaw skills contain at least one security vulnerability, according to the largest independent security audit of the OpenClaw ecosystem conducted by ClawSecure (https://www.clawsecure.ai). The audit analyzed 2,890+ popular OpenClaw agent skills drawn from the community-curated awesome-openclaw-skills list and the openclaw/skills repository, identifying 9,515 total security findings across the dataset. These represent the most widely installed agents in the OpenClaw ecosystem, which has surpassed 180,000 GitHub stars and attracts millions of weekly users since creator Peter Steinberger joined OpenAI in February 2026.
ClawSecure’s audit found that 30.6% of all audited skills contain vulnerabilities rated HIGH or CRITICAL in severity. ClawSecure’s analysis revealed that 99.3% of OpenClaw skills ship without a config.json permissions manifest, meaning users have no visibility into what system resources an agent will access before installation. Without a permissions manifest, an OpenClaw agent can request access to the file system, execute shell commands, read browser data, and make network calls to external servers with no user awareness. ClawSecure’s Watchtower monitoring system has tracked 661 code changes across registered skills, detecting cases where previously safe skills were modified post-installation to include suspicious behavior patterns.
The scope of findings spans every major vulnerability category that ClawSecure tracks. ClawSecure identified 539 skills exhibiting indicators consistent with the ClawHavoc malware campaign, a coordinated threat involving credential harvesting, command-and-control callbacks, and data exfiltration. ClawSecure also found widespread supply chain risks, including unpinned npm dependencies that allow compromised package versions to be silently pulled into a skill’s dependency tree. Credential exposure, unauthorized network calls, excessive permission requests, and ReDoS (Regular Expression Denial of Service) vulnerabilities were among the most common finding types across the dataset.
“The OpenClaw ecosystem is growing faster than its security infrastructure,” said J.D. Salbego, Founder of ClawSecure. “When nearly every skill ships without a permissions manifest and 41% contain vulnerabilities, users are installing agents on blind trust. ClawSecure exists to close that gap with real data and continuous monitoring, not just a one-time scan.”

ClawSecure’s proprietary 3-Layer Audit Protocol combines a behavioral analysis engine with 55+ threat patterns built specifically for OpenClaw, advanced static and behavioral analysis that traces execution paths across tool-calling chains, and full supply chain dependency scanning against known CVE databases. The platform detects the exploitation of what Palo Alto Networks (2026) calls the “Lethal Trifecta” of agentic AI risks: the combination of access to private data, exposure to untrusted content, and the ability to execute tools on the user’s behalf. ClawSecure’s Context-Aware Intelligence differentiates genuine threats from standard OpenClaw agent capabilities, reducing false positives that undermine developer trust in security tools. For example, ClawSecure’s audit of Peter Steinberger’s own flagship skill, peekaboo, scored it 95 out of 100, recognizing that its system-level capabilities are standard for a useful OpenClaw agent, while generic scanners flag it as suspicious.

ClawSecure’s Watchtower system provides continuous protection that one-time scanners cannot. Watchtower monitors all 2,890+ registered skills 24/7 using SHA-256 hash comparisons, automatically triggering a full re-audit through the 3-Layer Audit Protocol whenever a skill’s code is modified. This addresses the “sleeper agent” risk where a skill passes an initial review but is later updated to include malicious behavior. ClawSecure’s Watchtower has already detected 661 code changes across the registry, each triggering an immediate re-scan and updated security score.

ClawSecure has audited 2,890+ of the most popular OpenClaw skills and is the only platform providing free, public security audit reports with full OWASP ASI Top 10 coverage across all 10 categories. The platform achieves comprehensive coverage of the OWASP Agentic Security Initiative framework, which defines the industry standard for AI agent security risks including tool misuse, privilege escalation, goal hijacking, and supply chain compromise. ClawSecure is also the first OpenClaw security platform to publish formal NIST AI Risk Management Framework alignment documentation, available at the Trust Center (https://www.clawsecure.ai/trust).

The full dataset is available through ClawSecure’s public security registry (https://www.clawsecure.ai/registry), where developers can search, filter, and review audit results for any of the 2,890+ analyzed skills by security score, category, and risk level. ClawSecure’s Security Clearance API enables agent marketplaces and identity platforms to verify skill integrity programmatically before granting access, providing real-time SECURE, UNVERIFIED, or DENIED verdicts. The API is designed to complement identity verification platforms such as Moltbook, which provides creator identity and social reputation for its 2.2 million agents, while ClawSecure provides the code integrity verification that completes the trust stack. For users wondering how to check if an OpenClaw skill is safe before installing, ClawSecure’s scanner is free, requires no signup, and delivers results in under 30 seconds at https://www.clawsecure.ai.

Paul Bateman
ClawSecure, Inc
paul@clawsecure.ai
Visit us on social media:
LinkedIn
X

Legal Disclaimer:

EIN Presswire provides this news content “as is” without warranty of any kind. We do not accept any responsibility or liability
for the accuracy, content, images, videos, licenses, completeness, legality, or reliability of the information contained in this
article. If you have any complaints or copyright issues related to this article, kindly contact the author above.

Information contained on this page is provided by an independent third-party content provider. XPRMedia and this Site make no warranties or representations in connection therewith. If you are affiliated with this page and would like it removed please contact pressreleases@xpr.media

Argent LNG Submits Application to U.S. Department of Energy for Authorization to Export 25 MTPA of U.S. LNG

Argent LNG Submits Application to U.S. Department of Energy for Authorization to Export 25 MTPA of U.S. LNG

Increasing America’s ability to export LNG helps stabilize energy supply chains, strengthens relationships with key

March 12, 2026

Urban Comfort Redefined With 1-Bedroom Apartments in Cincinnati, OH

Urban Comfort Redefined With 1-Bedroom Apartments in Cincinnati, OH

CINCINNATI, OH, UNITED STATES, March 11, 2026 /EINPresswire.com/ — Core Redevelopment has broadened its portfolio of

March 12, 2026

M A Nakib Bridges Cloud Technology, Education, and Entrepreneurship Across Borders

M A Nakib Bridges Cloud Technology, Education, and Entrepreneurship Across Borders

This announcement reports a professional brief summarizing Cloud Architect and Microsoft Certified Trainer expands

March 12, 2026

Virginia Financial Educators Council Selects Ramona Jones, CEO of Jeunibe Financial Advisory, as Advisory Board Member

Virginia Financial Educators Council Selects Ramona Jones, CEO of Jeunibe Financial Advisory, as Advisory Board Member

Ramona Jones’ strategic approach to financial management and her passion for holistic planning make her a vital leader

March 12, 2026

When Dogs Begin Slowing Down on Stairs: Why Pet Owners Are Looking at Mobility Support, Including ZenaPet

When Dogs Begin Slowing Down on Stairs: Why Pet Owners Are Looking at Mobility Support, Including ZenaPet

Costa Mesa, California – March 12, 2026 – PRESSADVANTAGE – Many dog owners first notice changes in mobility during

March 12, 2026

Nova Warranty Redefines Extended Warranty Plans with Expanded High-Value Vehicle Coverage

Nova Warranty Redefines Extended Warranty Plans with Expanded High-Value Vehicle Coverage

WILMINGTON, DE – March 11, 2026 – PRESSADVANTAGE – Nova Warranty today announced the expansion of its extended warranty

March 12, 2026

Kitchen and Bath Masters Design & Remodeling Expands Premium Kitchen Services Throughout Arlington VA Region

Kitchen and Bath Masters Design & Remodeling Expands Premium Kitchen Services Throughout Arlington VA Region

March 11, 2026 – PRESSADVANTAGE – Kitchen and Bath Masters Design & Remodeling has announced an expansion of its

March 12, 2026

Bare Skin and Beauty Introduces Medik8 Niacinamide Peptides Serum for Enhanced Barrier Support

Bare Skin and Beauty Introduces Medik8 Niacinamide Peptides Serum for Enhanced Barrier Support

HILLARYS, WA – March 11, 2026 – PRESSADVANTAGE – Bare Skin and Beauty, a leading skin clinic with locations in Hillarys

March 12, 2026

Zum Königstuhl Showcases Authentic Swiss Traditional Food Heritage in Historic Zurich Setting

Zum Königstuhl Showcases Authentic Swiss Traditional Food Heritage in Historic Zurich Setting

Zurich, Zurich – March 12, 2026 – PRESSADVANTAGE – Zum Königstuhl, the renowned restaurant and bar located in Zurich's

March 12, 2026

Don Vallee’s Debut Thriller Flying Into Darkness Blends Procedural Realism with Psychological Suspense

Don Vallee’s Debut Thriller Flying Into Darkness Blends Procedural Realism with Psychological Suspense

Flying Into Darkness by Don Vallee Examines Control, Crime and Moral Obsession ORLANDO, FL, UNITED STATES, March 11,

March 12, 2026

Why California Families Should Attend a Rugby Match This Year

Why California Families Should Attend a Rugby Match This Year

California Legion are preparing to launch a statewide home match tour ahead of the 2026 MLR season, bringing

March 12, 2026

California Arts Council Launches 50th Anniversary Awards & Creative Impact Campaign

California Arts Council Launches 50th Anniversary Awards & Creative Impact Campaign

The California Arts Council announces a year-long campaign and awards ceremony celebrating 50 years of impact with

March 12, 2026

BGSF, Inc. Reports Fourth Quarter and Fiscal Year 2025 Financial Results

BGSF, Inc. Reports Fourth Quarter and Fiscal Year 2025 Financial Results

BG Staffing Realigns Go-to-Market Strategy to Drive Greater Clarity and Effectiveness PLANO, TX / ACCESS Newswire /

March 11, 2026

Bluente Launches Open-Source MCP Server, Bringing Format-Preserving Document Translation Directly Into AI Workflows

Bluente Launches Open-Source MCP Server, Bringing Format-Preserving Document Translation Directly Into AI Workflows

New integration lets AI agents translate documents across 120+ languages without leaving the tools developers and

March 11, 2026

Marilyn Suey, Founder of The Diamond Group Wealth Advisors, Warns Taxes, Creditors, Divorce Can Threaten Family Legacy

Marilyn Suey, Founder of The Diamond Group Wealth Advisors, Warns Taxes, Creditors, Divorce Can Threaten Family Legacy

Without the right strategies in place, taxes, lawsuits, and even family circumstances like divorce can erode what you

March 11, 2026

Aerogelic Ballooning Marks Nearly Five Decades of Safe Hot Air Balloon Operations Amid Growing Adventure Tourism Market

Aerogelic Ballooning Marks Nearly Five Decades of Safe Hot Air Balloon Operations Amid Growing Adventure Tourism Market

AZ, UNITED STATES, March 11, 2026 /EINPresswire.com/ — Aerogelic Ballooning, a hot air balloon company operating in

March 11, 2026

New Insights Highlight Importance of Outcome‑Focused Project Delivery

New Insights Highlight Importance of Outcome‑Focused Project Delivery

Successful projects prioritise outcomes over outputs to deliver real organisational value. Adopting an outcome-focused

March 11, 2026

The Five Case Model: Strengthening Public Investment Through Smarter, Evidence‑Based Decision Making

The Five Case Model: Strengthening Public Investment Through Smarter, Evidence‑Based Decision Making

The Five Case Model helps governments make smarter, evidence‑based investment decisions that deliver real public value.

March 11, 2026

Why certification and real skills matter more in an AI-driven workplace

Why certification and real skills matter more in an AI-driven workplace

In an AI-driven world, verified certification and real-world skills are essential for proving authentic professional

March 11, 2026

Certified Aviation Services Recognized by Department of Defense as Approved SkillBridge Industry Partner

Certified Aviation Services Recognized by Department of Defense as Approved SkillBridge Industry Partner

Program will provide transitioning service members with hands-on exposure to civilian aviation maintenance operations

March 11, 2026

Midtown Las Vegas Secures C-PACE Approval for Next Phase of Mixed-Use Tower Development

Midtown Las Vegas Secures C-PACE Approval for Next Phase of Mixed-Use Tower Development

Securing C-PACE approval is an important step in executing a disciplined and forward-looking capital strategy”— Anna

March 11, 2026

Copper Tech Introduces Copper-Infused Compression Golf Gloves Designed to Support Grip and Hand Comfort

Copper Tech Introduces Copper-Infused Compression Golf Gloves Designed to Support Grip and Hand Comfort

Direct-to-consumer golf brand expands focus on performance gear designed for comfort, grip stability, and durability

March 11, 2026

Iffel International and WunderMarx Form Strategic Alliance to Strengthen Corporate Reputation in the Age of AI

Iffel International and WunderMarx Form Strategic Alliance to Strengthen Corporate Reputation in the Age of AI

Collaboration integrates marketing and public relations to support revenue growth, investor confidence and market trust

March 11, 2026

Idlewild Burg, Inc. Acquires Language Solutions, Inc., Expanding Language Access Across the Americas and Globally

Idlewild Burg, Inc. Acquires Language Solutions, Inc., Expanding Language Access Across the Americas and Globally

Acquisition brings together LSI, Korn, and Zaum to deliver scalable, ISO certified language and accessibility solutions

March 11, 2026

Structured Press Releases Maintain Relevance as Artificial Intelligence Reshapes Online Search

Structured Press Releases Maintain Relevance as Artificial Intelligence Reshapes Online Search

Artificial intelligence systems rely on context and structure when interpreting information across the internet”— Brett

March 11, 2026

BingerLabs Unveils PRO Line: The Next Step in the Evolution of Pain Recovery & Restorative Wellness

BingerLabs Unveils PRO Line: The Next Step in the Evolution of Pain Recovery & Restorative Wellness

Science-Driven Performance Solutions Rooted in the Integration of Mind, Body, and Spirit Wellness is not isolated to

March 11, 2026

Primary Care Physicians Play Key Role in Diagnosing and Treating Minor Skin Conditions

Primary Care Physicians Play Key Role in Diagnosing and Treating Minor Skin Conditions

Primary care providers routinely evaluate a wide range of skin conditions during everyday appointments”— Chad Carrone

March 11, 2026

Thompson Builders Completes $22.1M Yerba Buena Island Hillcrest Road Improvement Project

Thompson Builders Completes $22.1M Yerba Buena Island Hillcrest Road Improvement Project

SAN FRANCISCO, CA, UNITED STATES, March 11, 2026 /EINPresswire.com/ — Thompson Builders Corporation (TBC) announces

March 11, 2026

CELSIUS Rock ‘n’ Roll Running Series Las Vegas Takes Over The Las Vegas Strip for the World’s Largest Running Party

CELSIUS Rock ‘n’ Roll Running Series Las Vegas Takes Over The Las Vegas Strip for the World’s Largest Running Party

I think it is truly a party, and it is an honor to be able to run in such a unique place as this. Having…

March 11, 2026

Family Law Attorney Krista Nash Shares Research-Based Strategies to Reduce Conflict and Protect Children During Divorce

Family Law Attorney Krista Nash Shares Research-Based Strategies to Reduce Conflict and Protect Children During Divorce

ARVADA, CO – March 11, 2026 – PRESSADVANTAGE – Children First Family Law has announced the publication of a new article

March 11, 2026

RestorePro Strengthens Regional Disaster Preparedness Partnerships

RestorePro Strengthens Regional Disaster Preparedness Partnerships

SANDUSKY, OH – March 11, 2026 – PRESSADVANTAGE – RestorePro Disaster Cleanup & Restoration has announced the

March 11, 2026

T-RAN Releases New Gospel Single ‘More of You’, Inviting Listeners Into a Message of Faith and Surrender

T-RAN Releases New Gospel Single ‘More of You’, Inviting Listeners Into a Message of Faith and Surrender

This song came from a season where I had nothing left to give but my yes”— T-RAN CHATTANOOGA, TN, UNITED STATES, March

March 11, 2026

LaPour Achieves 100% Lease-Up at Creekside Centennial Tech Center in Centennial, CO

LaPour Achieves 100% Lease-Up at Creekside Centennial Tech Center in Centennial, CO

Creekside was intentionally designed to serve small and mid-sized users who need dock and drive-in loading, higher

March 11, 2026

Red Coral Universe Supports Independent Filmmakers at 2nd Annual LATNBFF

Red Coral Universe Supports Independent Filmmakers at 2nd Annual LATNBFF

The Los Angeles-based film festival takes place on Thursday, March 12 followed by limited run streaming on Red Coral

March 11, 2026

Andy Cooney Releases New Single & Music Video for ‘Everybody’s Irish (You Know The Way)’

Andy Cooney Releases New Single & Music Video for ‘Everybody’s Irish (You Know The Way)’

The new single and music video for "Everybody's Irish (You Know The Way)" is the St. Patrick's Day anthem nobody knew

March 11, 2026

Pet Business Insurance to Connect With Grooming Professionals at GROOM’D 2026 Expo

Pet Business Insurance to Connect With Grooming Professionals at GROOM’D 2026 Expo

Pet industry insurance specialists will offer policy reviews and coverage guidance for grooming professionals at

March 11, 2026

Vikram Reddy Shares Enterprise Data Warehouse Playbook from Medicaid and AIG

Vikram Reddy Shares Enterprise Data Warehouse Playbook from Medicaid and AIG

Real-world healthcare data architecture lessons from a data engineer who built large-scale Medicaid and insurance

March 11, 2026

Short-Form Video Emerges as a Foundational Element in Modern Digital Marketing Strategy

Short-Form Video Emerges as a Foundational Element in Modern Digital Marketing Strategy

Short-form video reflects a fundamental change in how information moves through the internet”— Brett Thomas NEW

March 11, 2026

Kommerce channels 80s–90s graffiti into new streetwear collection

Kommerce channels 80s–90s graffiti into new streetwear collection

In homage to NYC’s pioneering graffiti era, the brand’s designs emphasize storytelling over tags, turning garments into

March 11, 2026

Vishal & Sheykhar Announce U.S. Return with ‘The Superhit Tour’ in July 2026

Vishal & Sheykhar Announce U.S. Return with ‘The Superhit Tour’ in July 2026

Vishal & Sheykhar bring “The Superhit Tour” to San Jose, Dallas, Nashville, and South Florida following a sold-out

March 11, 2026