Skip to content

v1.4.0 β€” OpenClaw/ClawHavoc + Agent-Skill Security

Latest

Choose a tag to compare

@cruzgio cruzgio released this 18 Jun 05:30

πŸ›‘οΈ v1.4.0 β€” OpenClaw / ClawHavoc + Agent-Skill Security (June 2026)

The agent-skill ecosystem became 2026's defining AI attack surface. This release documents the OpenClaw / ClawHub crisis and the defensive tooling that emerged in response.

Threat Intelligence

  • OpenClaw crisis β€” 135,000+ exposed instances (63–93% no auth); 60–138 CVEs in five months; one-click RCE (CVE-2026-25253); admin-without-creds (CVE-2026-22172/32922, CVSS 9.9).
  • ClawHavoc β€” up to 1,184 malicious ClawHub skills (~12% of registry at audit), AMOS payload, "ClickFix 2.0" social engineering through SKILL.md.
  • MCP exposure at scale β€” ~12,520 Internet-accessible MCP services (Censys); ~40% no-auth; VIPER-MCP found 106 zero-days / 67 CVEs; OX poisoned 9 of 11 marketplaces.

New Tools (all AI-specific, open-source)

Agent Threat Rules (ATR), Cisco DefenseClaw / MCP Scanner / Skill Scanner, AgentAuditKit, mcp-audit, SkillSpector, VIPER-MCP.

New Detection Rules (Sigma 13–16)

Unauthorized agent-config modification Β· compound read-and-exfiltrate Β· unauthenticated MCP exposure Β· ClickFix-style encoded prerequisite in skill manifests.

New Dorks (KEYWORD convention)

Agent-skill / OpenClaw config exposure, fake-skill/brand-impersonation detection, exposed MCP endpoints β€” all parameterized for authorized self-audit.

Responsible-use note

This release documents detection and self-audit. It deliberately does not publish live malicious skill names or step-by-step payload mechanics.

Full changelog: CHANGELOG.md