AUTO-UPDATED

OpenClaw: risks for agent users and how to mitigate them

The rapidly growing AI agent ecosystem OpenClaw faces significant security challenges as researchers identify hundreds of vulnerabilities and widespread distribution of malicious skills targeting enterprise environments and sensitive data.

Key Points

  • OpenClaw allows users to automate complex tasks using natural language instructions and downloadable "skills" from the ClawHub marketplace.
  • Since February 2026, approximately 530 vulnerabilities have been documented, many involving insecure data storage and excessive system privileges.
  • Security researchers identified over 600 malicious skills distributed by 24 accounts, with more than 1,100 suspicious accounts created since January.
  • Malicious skills often bypass traditional security by using natural language commands that execute harmful actions, detected by Kaspersky as HEUR:Trojan.ANSI.MalClaw.gen.
  • Organizations are advised to implement layered security, including the Kaspersky Scan Engine, to inspect skills and isolate AI agents from critical infrastructure.

Why it Matters

The widespread adoption of OpenClaw in professional settings creates significant risks for organizations that may be unaware of the security implications of automated AI agents. Without strict oversight and technical safeguards, these tools can be exploited to hijack systems or exfiltrate sensitive data through malicious third-party scripts.
Securelist.com Published by Kaspersky
Read original