Malicious OpenClaw Skills Turned a Viral Agent into a Security Warning

Koi Security reported 341 malicious skills posing as useful OpenClaw add-ons, showing why agent extensions need software-level scrutiny.

The risky part was the add-on

OpenClaw had become one of the most talked-about open-source personal agents when Koi Security published a serious finding on 1 February: its researchers had identified 341 malicious skills posing as useful add-ons. Some pretended to offer useful features while installing password-stealing malware.

1 February 2026Koi Security published its findings
341malicious skills identified in the original research
Targeted dataAPI keys, wallet keys, SSH credentials, and browser passwords

Why this matters

A skill is not merely a clever prompt. It can contain instructions, scripts, dependencies, and access to the same files or credentials the agent can reach. Installing one from an unknown publisher can be much closer to installing software than adding a browser bookmark.

Official-looking name

Can still belong to an unrelated publisher.

Local agent access

Can expose more than a normal web chat.

What OpenClaw users should check

Stop new installs

Give the ecosystem time to be reviewed.

Check existing skills

Remove anything unneeded or unverifiable.

Rotate exposed secrets

Replace keys present on a possibly affected machine.

Rebuild if infected

Use a clean system instead of trusting malware removal alone.

Pause before adding any skill. Check its publisher, source code, release history, permissions, dependencies, and reports from other users. Run new skills in an isolated environment without browser profiles, wallets, SSH keys, API keys, or personal documents.

  • The skill has a known publisher and readable source.
  • Dependencies come from expected repositories.
  • The test account contains no valuable secrets.
  • Network and file access are limited.

OpenClaw's rapid growth made experimentation easy, but it also made trust hard to judge. The safest default was to use fewer skills, read what they did, and give the agent far less access than the main computer owner.

Need more practical IT guides?

Explore step-by-step tutorials, expert insights, and actionable guidance to help you work smarter, stay secure, and solve real problems.

Browse More Articles