The post OpenClaw skill platform raises security concerns as AI agent adoption accelerates appeared on BitcoinEthereumNews.com. Recent research shows that OpenClawThe post OpenClaw skill platform raises security concerns as AI agent adoption accelerates appeared on BitcoinEthereumNews.com. Recent research shows that OpenClaw

OpenClaw skill platform raises security concerns as AI agent adoption accelerates

For feedback or concerns regarding this content, please contact us at crypto.news@mexc.com

Recent research shows that OpenClaw’s skill-scanning system is not a secure boundary. Posting third-party skills remains a problem for AI agent creation and usage. 

OpenClaw skills still pose security threats, and the recent skill-scanning system is not a secure boundary, according to recent security expert research. Skill scanning has been proposed as a gateway for skill publishers, aiming to intercept potentially malicious data payloads or malicious elements of the skill itself. 

As Cryptopolitan reported, third-party services have already posed security risks, and AI agent adoption is accelerating and worsening the problem. 

OpenClaw allows the user to create agents and run them on a local machine or a server. However, skills immediately alongside OpenClaw, and may inherit the same access to resources and tools. Since some skills involve sensitive tasks such as wallet access or on-chain interactions, the skill sets posted by third parties remain a risk. 

How does OpenClaw check skills for malicious intent? 

Recent research showed Clawhub uses VirusTotal, as well as OpenClaw’s internal moderation system. The results of those checks classify the skills and set up user warnings during installation. 

This system is still imperfect and may deem harmless or even potentially harmful skills. A problem arises when VirusTotal flags the skill as suspicious, and OpenClaw as benign. The user is shown a warning, and may still confirm the skill installation. Skills fully flagged as malicious are not allowed for downloads. 

OpenClaw also offers sandboxing and runtime controls, but these are optional and do not constitute a hard default boundary for third-party skills. OpenClaw leaves Docker-based sandboxing optional, and some tools remain available with it switched off. 

Users also choose the direct path because sandbox environments can be difficult to deploy, and some skills break down. This also means that the platform depends on reviews and warnings, a system that is not directly protective when running agent skills. 

Can OpenClaw catch malicious skills? 

OpenClaw has already implemented some security measures, including checks for behaviors specifically linked to catch code that can read secrets and send them out. This approach is used in traditional security to detect suspicious processes, requests, and other behaviors. 

AI agent skills are harder to scan because the inputs involve both code and natural-language instructions, as well as runtime behavior. Traditional security may have blind spots for agentic behaviors.

The next layer is to use AI scanning to catch more risky behaviors that weren’t caught by a static search or the usual regular expression approach. AI agents can give a glimpse into the internal consistency of skills, while not being exhaustive of the potential for exploits. They search for the most obvious exploitable code or general inconsistencies. 

Researchers noted the OpenClaw checks and moderation system was fast to approve skills, while VirusTotal sometimes took days to flag the addition. It was also possible to add exploits to already approved skills. This meant that the OpenClaw process could proclaim skills were benign when they could contain unexpected behaviors. 

For AI agent developers, researchers recommend sandboxing or using tools to prevent skills from running, even if they are flagged as benign. The researchers called for skill platforms to assume that normal-looking skills may hide exploits and to avoid using them in high-value environments, potentially granting access to crypto wallets or other sensitive information.

Source: https://www.cryptopolitan.com/openclaw-skill-platform-raises-security-concerns-as-ai-agent-adoption-accelerates/

Market Opportunity
Notcoin Logo
Notcoin Price(NOT)
$0.0004127
$0.0004127$0.0004127
-0.16%
USD
Notcoin (NOT) Live Price Chart
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact crypto.news@mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

iCapital® Acquires Hexure to Create the Industry’s First End-to-End Annuity and Insurance Technology Platform

iCapital® Acquires Hexure to Create the Industry’s First End-to-End Annuity and Insurance Technology Platform

The acquisition empowers financial advisors, distributors, and insurance carriers with a single integrated platform iCapital1, the global fintech company shaping
Share
Globalfintechseries2026/03/17 22:02
CME Group to launch options on XRP and SOL futures

CME Group to launch options on XRP and SOL futures

The post CME Group to launch options on XRP and SOL futures appeared on BitcoinEthereumNews.com. CME Group will offer options based on the derivative markets on Solana (SOL) and XRP. The new markets will open on October 13, after regulatory approval.  CME Group will expand its crypto products with options on the futures markets of Solana (SOL) and XRP. The futures market will start on October 13, after regulatory review and approval.  The options will allow the trading of MicroSol, XRP, and MicroXRP futures, with expiry dates available every business day, monthly, and quarterly. The new products will be added to the existing BTC and ETH options markets. ‘The launch of these options contracts builds on the significant growth and increasing liquidity we have seen across our suite of Solana and XRP futures,’ said Giovanni Vicioso, CME Group Global Head of Cryptocurrency Products. The options contracts will have two main sizes, tracking the futures contracts. The new market will be suitable for sophisticated institutional traders, as well as active individual traders. The addition of options markets singles out XRP and SOL as liquid enough to offer the potential to bet on a market direction.  The options on futures arrive a few months after the launch of SOL futures. Both SOL and XRP had peak volumes in August, though XRP activity has slowed down in September. XRP and SOL options to tap both institutions and active traders Crypto options are one of the indicators of market attitudes, with XRP and SOL receiving a new way to gauge sentiment. The contracts will be supported by the Cumberland team.  ‘As one of the biggest liquidity providers in the ecosystem, the Cumberland team is excited to support CME Group’s continued expansion of crypto offerings,’ said Roman Makarov, Head of Cumberland Options Trading at DRW. ‘The launch of options on Solana and XRP futures is the latest example of the…
Share
BitcoinEthereumNews2025/09/18 00:56
Top Crypto to Buy Now for 2026? Analysts Mention Mutuum Finance Under $0.05

Top Crypto to Buy Now for 2026? Analysts Mention Mutuum Finance Under $0.05

Investors searching for the top crypto to buy now for 2026 are increasingly balancing two strategies at once: maintaining exposure to established market leaders
Share
Techbullion2026/03/17 22:08