The risky part was the add-on
OpenClaw had become one of the most talked-about open-source personal agents when Koi Security published a serious finding on 1 February: its researchers had identified 341 malicious skills posing as useful add-ons. Some pretended to offer useful features while installing password-stealing malware.
Why this matters
A skill is not merely a clever prompt. It can contain instructions, scripts, dependencies, and access to the same files or credentials the agent can reach. Installing one from an unknown publisher can be much closer to installing software than adding a browser bookmark.
Can still belong to an unrelated publisher.
Can hide a download or command.
Can expose more than a normal web chat.
What OpenClaw users should check
Give the ecosystem time to be reviewed.
Remove anything unneeded or unverifiable.
Replace keys present on a possibly affected machine.
Use a clean system instead of trusting malware removal alone.
Pause before adding any skill. Check its publisher, source code, release history, permissions, dependencies, and reports from other users. Run new skills in an isolated environment without browser profiles, wallets, SSH keys, API keys, or personal documents.
- The skill has a known publisher and readable source.
- Dependencies come from expected repositories.
- The test account contains no valuable secrets.
- Network and file access are limited.
OpenClaw's rapid growth made experimentation easy, but it also made trust hard to judge. The safest default was to use fewer skills, read what they did, and give the agent far less access than the main computer owner.
