Home AI ClawHub Ranking Manipulation Lets Malicious Skills Automatically Infect AI Agents

ClawHub Ranking Manipulation Lets Malicious Skills Automatically Infect AI Agents

0
ClawHub Skills Infect Agents

The explosive growth of OpenClaw in early 2026 has transformed AI from a simple query tool into a powerful automated assistant. Agent Skills allow these AI systems to acquire new capabilities.

However, they have also become a prime entry point for attackers. A recent scan of over 50,000 skills on ClawHub, OpenClaw’s official marketplace, revealed covert attack methods that successfully bypass standard security measures.

Agent Skills represent a completely new and highly dangerous attack surface. Unlike older vulnerabilities, these skills run directly in a user’s environment with full permissions for file access, network communication, and shell execution.

Recognizing this shift, OWASP released the Top 10 Agentic Skills in April 2026 to systematically categorize these risks. The ecosystem exploded from zero to 50,000 skills in just 90 days, bringing significant security challenges along with it.

Even after ClawHub introduced multi-layered security detection following a massive wave of attacks, severe threats remain.

Attackers are simply evolving their tactics to outsmart platform defenses, moving away from explicit malicious code to highly sophisticated disguises.

ClawHub Skills Infect Agents

One of the most alarming discoveries is a ranking manipulation vulnerability identified by the Silverfort research team in March 2026. Attackers found they could send unauthenticated requests to inflate the download count of any skill infinitely.

Silverfort demonstrated this by uploading a skill disguised as an Outlook integration, embedding a data-stealing payload, and boosting it to the number one spot on ClawHub.

ClawHub Skills Infect Agents (Source: tencent)

This manipulation deceives not only human users but also the AI agents themselves. When functioning autonomously, OpenClaw agents prioritize installing tools with the highest download counts.

Consequently, achieving a high ranking allows malicious skills to automatically infect AI agents without requiring sophisticated code to bypass security scans.

The threat landscape is also heavily impacted by direct supply chain attacks. The ClawHavoc incident in February 2026 remains the largest attack in this space, where threat actors used typosquatting to impersonate popular tools.

ClawHub Skills Infect Agents (Source: tencent)

This led to over 247,000 installations of malicious skills that deployed the Atomic Stealer Trojan.

Beyond ranking manipulation and typosquatting, researchers found highly covert backdoors that pass ClawHub’s official security checks. One sample disguised itself as a distributed state recovery tool.

It bypassed static detection by fetching a serialized object from a remote server, decoding it through multiple layers of obfuscation, and executing arbitrary code via Python’s insecure deserialization.

The attacker never had to write malicious commands directly into the code, highlighting a significant blind spot in current platform defenses, tencent said.

These vulnerabilities are symptoms of a broader systemic risk across the AI tool supply chain. Data shows that large-scale, automated skill development is already underway.

Just 20 developers account for nearly 13% of all skills on ClawHub, with some accounts generating over ten skills per day. This mass production enables attackers to flood the marketplace with disguised or low-quality samples.

Follow us on Google News , LinkedIn and X to Get More Instant UpdatesSet Cyberpress as a Preferred Source in Google.

NO COMMENTS

LEAVE A REPLY

Please enter your comment!
Please enter your name here

Exit mobile version