OpenClaw, NVIDIA release ClawHub security dataset
OpenClaw, in collaboration with NVIDIA, has open-sourced a Hugging Face dataset of security scans for 67,453 skills registered on its ClawHub marketplace. The release includes threat assessments and static/dynamic analyses to help the developer community establish robust guardrails against supply chain exploits.
While open-sourcing security scans increases ecosystem transparency, static analyses and signature matching alone cannot fully protect autonomous agents from runtime exploits or dynamic prompt injections.
- –Securing AI agent marketplaces requires proactive runtime sandboxing and behavioral policy enforcement rather than relying solely on pre-publication repository scanning.
- –Open-sourcing this dataset allows researchers to study the threat landscape of agent skills, potentially exposing common attack patterns used in recent campaigns like ClawHavoc.
- –Collaborative efforts between platform creators like OpenClaw and infrastructure giants like NVIDIA underscore a growing industry-wide push to formalize security standards for agentic systems.
DISCOVERED
1h ago
2026-06-01
PUBLISHED
1h ago
2026-06-01
RELEVANCE
AUTHOR
steipete