Malicious Skills disguised as useful tools exist in the OpenClaw / AI Agent ecosystem.
Free scanner, daily-updated threat database, protect your system and data.
--repository flag to bypass official registry. Multiple confirmed victims.install-ai-skill- carry suspected RCE risk. Unknown publisher, no legitimate maintainer.npm install agent-reach --repository https://…".env file. 312 customer records were exfiltrated before she noticed.
Threat database is updated daily. No ads, no paywalls, no VC money.
If this helped you, buy me a coffee — it keeps the lights on.
Or submit a threat report — that helps too.
Daily top-3 money-making OpenClaw patterns, 10 real case studies, full scripts + pricing strategy + growth paths.
Enter ClawAcademy →