← Back to Webthreepedia
WEBTHREEPEDIA RESEARCH

[DEEP DIVE] The Supply Chain Goes Deeper: Skills, MCP, Ecosystem (9/10)

Zephyra|February 20, 2026|BPF
EXECUTIVE SUMMARY

OpenClaw's supply chain extends far beyond a single application. The ClawHub marketplace, which hosts 10,700+ agent skills, has become a distribution channel for malware, credential theft, and persistent backdoors. Snyk's ToxicSkills audit of 3,984 skills found that 36.82% — 1,467 packages — cont...

"ClawHub is the npm registry for AI agents — with all the same problems, except the blast radius is your entire machine." — Snyk ToxicSkills Research Team, February 2026

Executive Summary

OpenClaw's supply chain extends far beyond a single application. The ClawHub marketplace, which hosts 10,700+ agent skills, has become a distribution channel for malware, credential theft, and persistent backdoors. Snyk's ToxicSkills audit of 3,984 skills found that 36.82% — 1,467 packages — contained at least one security flaw. 534 had critical-level issues. 76 were confirmed malicious payloads. The Koi Security-identified ClawHavoc campaign accounted for 1,184 malicious skills alone, with one threat actor uploading 677 packages. The barrier to entry for publishing: a GitHub account seven days old and a Markdown file.

This is not a bug. It is the architecture functioning as designed. Skills execute with the same OS-level privileges as the OpenClaw process. MCP servers extend the attack surface through additional integration points. The AI agent itself can write new skills, creating a self-modifying system where the line between tool and threat dissolves. On February 17, 2026, a separate supply chain attack compromised the Cline CLI npm package, using a stolen publish token to silently install OpenClaw on approximately 4,000 developer machines — demonstrating that the contagion spreads beyond OpenClaw's own ecosystem.

Table of Contents

  1. The Registry Problem: ClawHub's Open Door
  2. Anatomy of a Malicious Skill
  3. Prompt Injection: Attacking the AI, Not the Human
  4. The Credential Hemorrhage
  5. MCP Servers: The Other Extension Vector
  6. Self-Modifying Agents: When the Tool Programs Itself
  7. The Cline Incident: Contagion Beyond the Ecosystem
  8. The Trust Chain Collapse
  9. Retroactive Security: SecureClaw, ClawSec, and the Patching Problem
  10. Key Takeaways

The Registry Problem: ClawHub's Open Door

ClawHub launched as an open marketplace for OpenClaw skills — packaged sets of instructions that define how the AI agent performs tasks. By mid-February 2026, the registry contained 10,700+ skills. The publishing requirements: a SKILL.md Markdown file and a GitHub account at least one week old. No code signing. No static analysis. No manual review. No sandbox.

Snyk's ToxicSkills study, published February 5, 2026, scanned 3,984 skills from ClawHub and skills.sh — the largest publicly available corpus of agent skills. The findings:

  • 1,467 skills (36.82%) contained at least one security flaw of any severity
  • 534 skills (13.4%) had critical-level security issues
  • 76 confirmed malicious payloads designed for credential theft, backdoor installation, and data exfiltration

VirusTotal's independent analysis, using Gemini 3 Flash to perform security-focused analysis of skill packages, scanned more than 3,016 skills. Hundreds showed malicious characteristics. A single threat actor using the handle "hightower6eu" published 314 skills, all flagged as malicious.

Bitdefender placed the total count of malicious packages at approximately 900, representing roughly 20% of the ecosystem at the time of analysis.

These numbers describe a registry where between one in five and one in three packages pose a security risk. For comparison, the npm registry — which has faced its own supply chain crises — has never seen compromise rates approaching this percentage.

Anatomy of a Malicious Skill

The ClawHavoc campaign, first detected on January 27, 2026, and surging on January 31, used a multi-layered attack strategy. According to Koi Security's analysis, the malicious skills followed several patterns:

Typosquatting. Skills named better-polymarket, polymarket-all-in-one, and solana-wallet-tracker mimicked legitimate tools. Documentation appeared professional. Functionality appeared real.

Fake prerequisites. 335 skills instructed users to run terminal commands under the guise of "fixing the environment." Those commands installed Atomic Stealer (AMOS), a commodity macOS infostealer available on criminal marketplaces for $500–$1,000 per month.

Reverse shells. Functional-looking skills hid backdoor code that opened reverse shell connections to attacker-controlled servers.

Credential exfiltration. Skills silently uploaded the contents of ~/.clawdbot/.env — which stores API keys, OAuth tokens, and integration credentials — to external webhook endpoints.

Target data included exchange API keys, wallet private keys, SSH credentials, browser passwords, and bot configuration files. One attacker uploaded 677 packages in a single campaign.

Prompt Injection: Attacking the AI, Not the Human

The most architecturally significant finding from the ClawHavoc analysis: 91% of malicious skills included prompt injection. These skills did not merely contain malicious code — they embedded hidden instructions that manipulated the AI agent itself.

According to Snyk's research, the injected prompts caused OpenClaw to:

  • Silently execute curl commands to download additional payloads
  • Send credential data to external servers
  • Bypass safety guidelines and content filters
  • Suppress user-visible output while performing background operations

This represents a category of attack that has no precedent in traditional software supply chains. An npm package cannot convince Node.js to ignore its own security policies. A malicious skill can convince an AI agent to disregard its safety instructions.

Penligent's research demonstrated that attackers can modify OpenClaw's SOUL.md — the persistent context file that defines the agent's identity and behavioral boundaries — to introduce long-term behavioral changes. Once the memory file is compromised, the attack persists across sessions and restarts. The agent has been, in Penligent's terminology, "cognitively rootkitted."

As NIST's CAISI framework defines it, this constitutes "agent hijacking" — the lack of separation between trusted instructions and untrusted data allows attackers to redirect the agent's objective.

The Credential Hemorrhage

Beyond deliberately malicious skills, Snyk identified a separate problem: skills that leak credentials through negligence rather than malice.

283 skills (7.1% of the registry) contained instructions that exposed API keys, passwords, and personal data. Popular, functional skills like moltyverse-email and youtube-data instructed AI agents to handle secrets in ways that passed them through the LLM's context window and output logs in plaintext.

When a skill instructs the agent to "use this API key," the model stores the key in its conversation history. That history can be leaked to the model provider — Anthropic, OpenAI, or others — through standard API calls. The credential is no longer contained on the user's machine; it exists in a third-party inference pipeline.

This architectural flaw means that even legitimate, well-intentioned skills can transform OpenClaw into a credential exfiltration vector — not by design, but by the fundamental way LLM-based agents process information.

MCP Servers: The Other Extension Vector

The Model Context Protocol (MCP) provides a standardized interface for connecting AI models to external tools and data sources. OpenClaw supports MCP servers as an extension mechanism alongside skills. Each MCP server represents an additional attack surface.

CVE-2025-6514, a critical OS command-injection vulnerability in mcp-remote — a popular OAuth proxy for MCP servers with over 437,000 downloads — allowed malicious MCP servers to achieve remote code execution on client machines. The vulnerability effectively turned unpatched installations into supply chain backdoors.

Three additional vulnerabilities (CVE-2025-68145, CVE-2025-68143, CVE-2025-68144) in Anthropic's own Git MCP server enabled remote code execution via prompt injection, including path validation bypass and argument injection.

Invariant Labs demonstrated that a malicious MCP server could silently exfiltrate a user's entire WhatsApp message history by combining tool poisoning with a legitimate MCP server. The attack required no special permissions — it operated within the standard MCP trust model.

Users pull community-contributed MCP servers from open repositories with the same absence of verification that characterizes ClawHub. MCP tool poisoning — where malicious metadata manipulates the AI agent's behavior — represents what multiple security firms describe as a new, AI-native supply chain vector that traditional security tools do not monitor.

Self-Modifying Agents: When the Tool Programs Itself

OpenClaw can write its own skills. When it encounters a task it does not know how to perform, it generates the code required to accomplish it. Cisco's security analysis described this as the agent producing "vibe code" — functional but unreviewed scripts that execute with the agent's full system privileges.

This capability collapses the distinction between user, developer, and runtime. The AI agent is simultaneously:

  • A consumer of skills (pulling from ClawHub)
  • A developer of skills (writing its own)
  • An executor of skills (running with OS-level access)

A prompt injection attack that modifies the agent's behavior can cause it to write and execute malicious skills autonomously. The attacker does not need to publish a package to ClawHub. The compromised agent generates the payload locally, from memory that has been poisoned through a prior interaction.

Microsoft's security blog, published February 19, 2026, stated the core risk plainly: self-hosted agents combine "untrusted code and untrusted instructions into a single execution loop that runs with valid credentials." Their recommendation: assume compromise is possible, isolate the runtime, and be prepared to rebuild without delay.

The Cline Incident: Contagion Beyond the Ecosystem

On February 17, 2026, at 3:26 AM PT, an unauthorized party published Cline CLI version 2.3.0 to the npm registry using a compromised publish token. The package contained a modified package.json with one addition:

"postinstall": "npm install -g openclaw@latest"

For approximately eight hours, every developer who installed Cline CLI received an unauthorized OpenClaw installation. Approximately 4,000 downloads occurred before the package was deprecated at 11:30 AM PT. The compromised token was revoked and Cline released version 2.4.0 with OIDC-based publishing via GitHub Actions.

The incident demonstrated that OpenClaw's supply chain risk extends beyond its own ecosystem. A compromised dependency in an unrelated tool can install OpenClaw — with its full system access capabilities — on developer machines without consent. The attack chain is recursive: a supply chain compromise installs a tool that itself has supply chain vulnerabilities, each layer amplifying the risk of the one below it.

The Trust Chain Collapse

The complete trust chain in an OpenClaw deployment operates as follows:

  1. User trusts OpenClaw with system access (shell, files, credentials, 50+ integrations)
  2. OpenClaw trusts skills from ClawHub (no code signing, minimal vetting)
  3. Skills trust their dependencies (npm packages, external APIs, MCP servers)
  4. Dependencies trust their own dependencies (transitive risk, unbounded depth)

Any single link in this chain that breaks compromises every link above it. A malicious npm package inside a skill inside OpenClaw has the same access as OpenClaw itself: email, calendar, messaging, file system, shell commands, browser, GitHub tokens, Gmail API keys, Slack tokens.

Each of OpenClaw's 50+ integrations — Gmail, GitHub, Spotify, Obsidian, Twitter, and others — represents an OAuth token or API key stored locally. A supply chain compromise at any depth can exfiltrate all of them. Memory files stored in plain Markdown — containing daily notes, preferences, relationships, financial details — are readable by any process with disk access.

Retroactive Security: SecureClaw, ClawSec, and the Patching Problem

Following the security crisis, three security tools emerged:

SecureClaw, published by Adversa AI on February 16, 2026, provides 55 audit checks for OpenClaw installations and includes hardening modules. It operates as both a plugin and a skill, aligning with OWASP and MITRE agentic AI frameworks.

ClawSec, created by Prompt Security and published by SentinelOne, functions as a "skill-of-skills" — a security layer that wraps agents in drift detection, automated audits, and skill integrity verification.

ClawShield offers audit commands and auto-fix capabilities for common configuration issues.

These tools arrived weeks after the crisis began. They operate within the same architectural constraints they attempt to mitigate: they are skills that run inside the agent they are trying to protect, with no higher-privilege isolation boundary.

Aikido Security's assessment, titled "Why Trying to Secure OpenClaw is Ridiculous," stated the fundamental problem: "As long as AI agents need to process untrusted content to be useful, prompt injection remains unfixable." The security tools reduce low-effort attacks. They cannot address the architectural absence of privilege separation.

OpenClaw itself integrated VirusTotal scanning to hash skills and compare them against known malicious samples. The project's maintainers acknowledged it is "not a silver bullet" and that skills using "cleverly concealed prompt injection payloads may slip through the cracks." Signature-based detection addresses known threats. The ClawHavoc campaign demonstrated that novel payloads — prompt injections embedded in Markdown files — bypass traditional scanning entirely.

Key Takeaways

  • 36.82% of ClawHub skills contain security flaws according to Snyk's audit of 3,984 packages. 13.4% are critical. The registry's compromise rate has no precedent in traditional package ecosystems.
  • Skills execute with OS-level privileges. There is no sandbox, no code signing, and no mandatory review. Publishing requires only a week-old GitHub account and a Markdown file.
  • 91% of malicious skills used prompt injection — attacking the AI agent rather than the user, causing it to silently execute commands, exfiltrate data, and bypass safety controls.
  • MCP servers extend the attack surface through identical architectural weaknesses. CVE-2025-6514 turned 437,000+ installations of a popular MCP proxy into supply chain backdoors.
  • OpenClaw's self-modifying capability means a compromised agent can generate and execute malicious code autonomously, without requiring a published package.
  • The Cline CLI incident proved the contagion spreads beyond OpenClaw's ecosystem — a compromised npm token in an unrelated tool installed OpenClaw on 4,000 developer machines.
  • Post-crisis security tools (SecureClaw, ClawSec, ClawShield) operate within the same unprivileged boundary they attempt to protect, addressing symptoms rather than the architectural absence of isolation.

Conclusion

The supply chain problem in OpenClaw is not a collection of individual vulnerabilities to be patched. It is the natural consequence of an architecture that grants unrestricted system access to an AI agent, allows that agent to load arbitrary code from an unvetted marketplace, and permits it to write and execute its own code without review.

Traditional software supply chain attacks — SolarWinds, the event-stream npm incident, the ua-parser-js compromise — required human attackers to craft and maintain malicious code. OpenClaw's architecture introduces a new variable: an AI agent that can be manipulated through language into becoming the attacker. The supply chain does not end at the code. It extends through every piece of text the agent processes, every webpage it reads, every email it receives.

Microsoft's guidance — assume compromise, isolate, constrain, monitor, prepare to rebuild — is the only defensible posture for organizations that proceed with deployment. For the 300,000–400,000 individuals running OpenClaw on personal machines with their full digital lives accessible, that guidance arrives after the architecture has already been trusted.

Sources & References

  1. Snyk ToxicSkills: Malicious AI Agent Skills in ClawHub — Comprehensive audit of 3,984 ClawHub skills, February 2026
  2. 280+ Leaky Skills: How OpenClaw & ClawHub Are Exposing API Keys and PII — Snyk credential leak research
  3. VirusTotal: From Automation to Infection — VirusTotal analysis of weaponized skills
  4. Cisco: Personal AI Agents like OpenClaw Are a Security Nightmare — Cisco security assessment
  5. Cline CLI 2.3.0 Supply Chain Attack — The Hacker News, February 2026
  6. Microsoft: Running OpenClaw Safely — Microsoft Security Blog, February 19, 2026
  7. Penligent: The OpenClaw Prompt Injection Problem — Persistence and tool hijacking analysis
  8. Adversa AI: SecureClaw Launch — SecureClaw security tool, February 16, 2026
  9. Aikido: Why Trying to Secure OpenClaw is Ridiculous — Architectural critique
  10. Netizen: OpenClaw and the Expansion of the Software Supply Chain — Supply chain analysis, February 19, 2026
  11. SentinelOne: ClawSec Hardening OpenClaw Agents — ClawSec security tool
  12. SecurityWeek: OpenClaw Security Issues Continue — Ongoing security assessment
[DEEP DIVE] The Supply Chain Goes Deeper: Skills, MCP, Ecosystem (9/10) | Webthreepedia