Report Clawhub Malicious Skill

Use when a researcher, maintainer, or contributor found or suspects a malicious skill on ClawHub and needs a private reporting workflow: opening a GitHub private vulnerability report, preparing a proposal-only PR, creating `proposals/<GHSA-ID>/clawscan.yml`, running ClawScan against the malicious skill, and explaining what evidence belongs in private versus public channels.

OpenClaw e91c1cf 2 files · 4.7 KB Updated 9.1k repo stars

File contents

openclaw/clawscan/tree/main/skills/report-clawhub-malicious-skill commit e91c1cf1a3

Frequently asked questions

npx skillmds@latest add openclaw/report-clawhub-malicious-skill