logo

Skill Scanning Is Not a Security Boundary

ID: b20d8550-693f-55fe-8d1d-6e5fdf6e75a7

STIX ID: report--b20d8550-693f-55fe-8d1d-6e5fdf6e75a7

Feed Name: CertiK Blog

Threat Score
70/100

Date Published: 2026-03-16

Date Updated: 2026-06-11

...
...

This report analyzes OpenClaw's Clawhub marketplace security, demonstrating a plausible Skill that abused a URL-based import vulnerability to achieve arbitrary command execution on host systems; it shows how static scanners and AI moderation can be bypassed or delayed (e.g., VirusTotal pending), and argues that review-based defenses are brittle without default sandboxing and per-Skill permissions, concluding with recommendations to make isolation the default and enforce least-privilege capabilities.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.