Thank you for your interest in making the OpenClaw ecosystem safer. ClawSecure welcomes contributions from security researchers, OpenClaw developers, and community members.
If you've found a vulnerability, suspicious behavior, or malicious code in an OpenClaw skill:
- Check the registry first — Search the Verified Agent Registry to see if the skill has already been audited
- Submit a scan — Use the OpenClaw security scanner to run a free 3-Layer Audit on the skill
- File an issue — If you've found something the scanner didn't catch, open a Suspicious Skill Report issue in this repository with details
Please include the skill URL, a description of the suspicious behavior, and any reproduction steps.
Any publicly available OpenClaw skill can be scanned for free:
- Via URL — Paste any ClawHub or GitHub skill URL into the scanner at clawsecure.ai
- Via file upload — Upload a skill zip file directly through the scanner interface
Results are delivered in seconds as a full Security Audit Report covering all 10 OWASP ASI categories.
Have an idea for improving ClawSecure? Open a Feature Request issue. We're especially interested in:
- New threat patterns for OpenClaw-specific attack vectors
- Security Clearance API integration ideas
- Improvements to the Verified Agent Registry
- OWASP ASI coverage enhancements
Found a bug in the ClawSecure platform itself? Open a Bug Report issue with steps to reproduce.
If you've found a security vulnerability in ClawSecure itself (not in an OpenClaw skill), please see SECURITY.md for our responsible disclosure process. Do not open a public issue for security vulnerabilities.
We are committed to providing a welcoming and respectful environment for everyone contributing to OpenClaw security. Contributors are expected to:
- Be respectful and constructive in all interactions
- Focus on the technical merits of security findings
- Avoid disclosing active vulnerabilities publicly before responsible disclosure
- Credit original researchers when referencing prior work
Visit clawsecure.ai, email us at contact@clawsecure.ai, or reach out on X/Twitter at @ClawSecure.