π‘οΈ v1.4.0 β OpenClaw / ClawHavoc + Agent-Skill Security (June 2026)
The agent-skill ecosystem became 2026's defining AI attack surface. This release documents the OpenClaw / ClawHub crisis and the defensive tooling that emerged in response.
Threat Intelligence
- OpenClaw crisis β 135,000+ exposed instances (63β93% no auth); 60β138 CVEs in five months; one-click RCE (CVE-2026-25253); admin-without-creds (CVE-2026-22172/32922, CVSS 9.9).
- ClawHavoc β up to 1,184 malicious ClawHub skills (~12% of registry at audit), AMOS payload, "ClickFix 2.0" social engineering through
SKILL.md. - MCP exposure at scale β ~12,520 Internet-accessible MCP services (Censys); ~40% no-auth; VIPER-MCP found 106 zero-days / 67 CVEs; OX poisoned 9 of 11 marketplaces.
New Tools (all AI-specific, open-source)
Agent Threat Rules (ATR), Cisco DefenseClaw / MCP Scanner / Skill Scanner, AgentAuditKit, mcp-audit, SkillSpector, VIPER-MCP.
New Detection Rules (Sigma 13β16)
Unauthorized agent-config modification Β· compound read-and-exfiltrate Β· unauthenticated MCP exposure Β· ClickFix-style encoded prerequisite in skill manifests.
New Dorks (KEYWORD convention)
Agent-skill / OpenClaw config exposure, fake-skill/brand-impersonation detection, exposed MCP endpoints β all parameterized for authorized self-audit.
Responsible-use note
This release documents detection and self-audit. It deliberately does not publish live malicious skill names or step-by-step payload mechanics.
Full changelog: CHANGELOG.md