openai

Skip to main content

Tag: openai

Agent Skill Security: ClawHub's Open Security Pipeline

Agent Skill Security: ClawHub’s Open Security Pipeline

Agent skill files have a reputation for being insecure, and that reputation is earned. When we launched ClawHub alongside OpenClaw, we were immediately targeted by actors who tried to publish skills bundling known malware. We partnered with VirusTotal to flag those skills and ban the publishers automatically. Traditional malware scanning is a relatively solved problem. Identifying agentic risk is not. A skill can claim to summarize your logs while bundling a script that ships them off your machine. A well-meaning skill can point your agent at a CLI that wipes production on the wrong flag....

Continue reading