Report a Malicious Skill

Found a skill that steals credentials, exfiltrates data, or installs backdoors? Report it so we can add it to our malicious skills database and warn others.

What to include:

  • Skill name and URL (ClawHub link or repo)
  • Description of malicious behavior observed
  • Any logs or evidence
Report via GitHub Issues

Security Vulnerability

Discovered a vulnerability in OpenClaw itself, the gateway, or the skill runtime? Responsible disclosure is welcome. We'll coordinate with the OpenClaw core team.

What to include:

  • Affected component and version
  • Steps to reproduce
  • Impact assessment (RCE, data leak, privilege escalation, etc.)
Submit via GitHub Security Advisories

General Feedback

Suggestions for new guides, skill requests, website improvements, or anything else. We read everything.

Open a Discussion on GitHub