Connect Clawsmith to your coding agent. Ship products like crazy.Unlimited usage during betaGet API Key →
← Back to dashboard
clawsmith.com/signal/openclaw-26-percent-skills-vulnerable
IssueUnderservedToolLive

26% of 31,000 OpenClaw agent skills contain at least one vulnerability

Cisco AI Defense team found over a quarter of all agent skills have vulnerabilities. Nine critical findings in the #1 ranked skill including active data exfiltration via silent curl commands and direct prompt injection bypassing safety guidelines.

Product Idea from this Signal

A security service that auto-patches OpenClaw CVEs within hours of disclosure before attackers exploit them

3.7k

OpenClaw shipped 9 CVEs in 4 days (March 2026) including a CVSS 9.9 privilege escalation affecting 135K+ exposed instances. Most operators have no way to know which CVEs affect their version, no automated patching, and no coordination between the flood of advisories (156+ total) and their actual attack surface. This tool continuously monitors CVE feeds, maps each advisory to your installed version and enabled features, and applies safe mitigations automatically while queuing risky patches for human approval.

SECURITYCLIDEVTOOLOPEN-SOURCESYSADMIN
CompetitiveView Opportunity →

Social Proof 0 sources

Gap Assessment

UnderservedExisting solutions leave gaps

ClawSec offers skill integrity verification. VirusTotal partnership provides daily scanning. But coverage is reactive not proactive — malicious skills can be installed before detection.