Observed Signal · Mar 31, 2026 · Security Report · Source: DEV Community · Impact: 3/5 · Sentiment: Negative
Re-Scan Finds Critical Security Issues in ClawHub Skills
A follow-up security scan of the top 50 ClawHub skills by the Rotifer Protocol found rapid ecosystem growth and the first occurrence of critical code-execution patterns. Total downloads for the Top 50 rose from 1.25M to over 3.5M in one week. The scan detected one eval() use and 115 system-command execution patterns concentrated in two self-evolving skills, producing 844 findings across ~25,000 lines of code. Two of the previously top-ranked skills were delisted (including the #1 with 311K downloads), 17 of 50 skills (34%) are flagged "Suspicious" by OpenClaw behavioral indicators, and the Grade A share fell from 88% to 78%. The report highlights author concentration (one maintainer owns 18 popular skills) and recommends multiple trust layers (V(g), OpenClaw, VirusTotal) for ecosystem safety. Scanner tools and full data are open source.
First detection of critical dynamic-execution patterns and delistings in a popular agent-skill ecosystem signals growing trust and safety risks as adoption accelerates; open-source data and tooling make findings actionable.
Track Real-Time Agent Skills Security Signals & Market Shifts
Polaris7 autonomous intelligence agents track regulatory filings, primary sources, executive changes, and deal flow 24/7. Create your free Explorer workspace to monitor these entities.
Key Takeaways & Evidence Grounding
- Total downloads across the Top 50 skills grew from 1.25M to over 3.5M in one week.
- One eval() call (S-01) and 115 system command execution patterns (S-02) were detected; most findings concentrate in two self-evolution skills.
- Two skills received Grade D for the first time; two top-10 skills (including #1 with 311K downloads and #3 with 170.9K) were delisted and flagged Suspicious.
- 17 of 50 Top skills (34%) are marked Suspicious by topclawhubskills.com / OpenClaw behavioral analysis.
- One author (@steipete) maintains 18 of the Top 50 skills (36% concentration).
Ontology Mapping & Concepts
Related Market Signals & Shifts
Recent verified developments and strategic activity across this market segment.
Snyk audit finds widespread malware in Claude skills
In February 2026 Snyk published the ToxicSkills audit, the first large-scale security review of public Claude Code skills, scanning 3,984 skills from ClawHub and skills.sh. The audit found extensive risks: 13.4% of skills had critical issues, 36% contained prompt-injection payloads, 1,467 distinct malicious payloads were identified, and 91% of confirmed malware combined natural‑language jailbreaks with executable shell payloads. The article outlines common attack patterns (prompt injections in descriptions, chained shell pipelines, and dependency-typo squats), a seven-step framework for auditing skills before installation, and examples of real skills rejected during a May 2026 review. It also cites Anthropic platform signals (Claude Code spec release in Dec 2025, a March 31, 2026 source leak, and a June 15 billing change) and describes a paid SkillVault bundle that ships 41 hand‑audited skills and public audit summaries.
Defending AI Agent Skills From Supply-Chain Attacks
A technical post explains a new supply-chain attack vector targeting AI agent 'skills' (SKILL.md files) which bypass package-manager protections and endpoint detection, allowing malicious instructions to run in high-trust developer environments. The author documents why existing defenses (pnpm/npm safeguards, EDR) fail against skill layers, cites that ClawHub contained 341 malicious skills (11.9%) of 2,857 in Feb 2026, and describes a practical mitigation—'skill-firewall'—that combines static analysis with LLM-based scanning for Claude Code / Cursor skill layers. The article also shares operational and UX lessons from building the tool, such as symlink attack vectors and preferring agent warnings over end-user alerts.
Audit AI Agent Skills for Credential and Instruction Risks
Security researchers warn that AI agent "skill" files are an underaudited supply-chain attack surface that can expose credentials and carry active malicious instructions. Capsule Security analysed hundreds of thousands of skill and code files and found thousands of distinct skills with hardcoded credentials and direct database write access. A separate disclosure documents a March 2026 campaign that used installation instructions inside skill metadata to install Remcos RAT and GhostLoader without further user interaction. The article outlines the attack surface (metadata/installation instructions, config, optional code) and gives a five-step audit process: inventory skills, scan metadata for credential patterns, review installation instructions, verify versions and provenance, and treat skill installs like package dependencies. Armor1 describes a two-pass skill security scanner that detects hardcoded credentials, malicious install steps, exfiltration patterns, and supply-chain risks.
Track Real-Time Market Signals & Shifts
Set up custom watchlists to receive automated, evidence-grounded executive digests whenever material signals or shifts occur across your tracked landscape.
