Koi Security and Snyk independently discovered hundreds of skills designed to steal your API keys, credentials, and data. Is your OpenClaw instance protected?
Skills are plain-text instructions. A malicious skill can tell your agent to exfiltrate API keys, store credentials in memory files, or open reverse shells — all without you knowing.
Skills instruct the agent to save API keys, tokens, and passwords into MEMORY.md — then exfiltrate them via curl or encoded URLs.
CVE-2026-25253Some skills ask for credit card numbers and CVC codes "for testing" — passing them through the LLM context where they get logged.
Snyk Pattern #2Advanced malicious skills execute shell commands to open backdoors on your server — persistent access for attackers.
CVE-2026-25157Each script detects your OS automatically and adapts — Linux (ufw, apt), macOS (pfctl, brew), or WSL.
Deep-scan any skill before installation. Detects all 12 known malicious patterns from the Snyk/Koi research.
oc-skill-scanner.shFull 8-point audit: skills, credentials, gateway, SSH, firewall, permissions, versions, OS security. JSON output.
oc-security-audit.shDeny-by-default with rate-limited SSH. Auto-detects web servers. UFW on Linux, pfctl on Mac.
oc-firewall-setup.shCIS-benchmark config: disable root, key-only auth, idle timeout, verbose logging. Auto-backup.
oc-ssh-harden.shStep-by-step hardening guide. Print it, tick boxes, sleep better. Covers network, auth, skills, and monitoring.
checklist.mdCurated list of audited, safe ClawHub skills. Updated as new skills are reviewed.
verified-skills.md"Researchers found 341 malicious 'skills' on AI agent marketplace ClawHub… skills could steal credentials, inject prompts, or open reverse shells."
"The fundamental problem is trust. Skills are just text that the AI agent follows. A malicious skill author can make your agent do anything your user can do."
"283 skills were found to be leaking user credentials through prompt injection and memory file exfiltration techniques."
--dry-run mode that shows exactly what it would do without making changes. The SSH hardening script auto-creates a backup before modifying anything. We recommend running dry-run first.
--json output, making it easy to integrate into CI pipelines. Run it as a pre-deploy check to catch misconfigurations.
341 malicious skills are already on ClawHub. Your API keys are worth more than €24.
🛡️ Harden My OpenClaw — €24