After the Party: Growth, Governance, and Security Scanning in the OpenClaw Agent Skill Ecosystem
cs.SE, cs.AI, cs.CY
Submitted: 2026-09-15
Updated: 2026-09-16
Comments: To appear in IEEE Digital Library as the 33rd Asia-Pacific Software Engineering Conference (APSEC 2026) conference proceedings. Accepted version, not camera ready version
Code: https://github.com/openclaw/openclaw
License: http://arxiv.org/licenses/nonexclusive-distrib/1.0/
Terminology
Sources
- Agent Skills in the Wild: An Empirical Study of Security Vulnerabilities at Scale
- Agent Skills: A Data-Driven Analysis of Claude Skills for Extending Large Language Model Functionality
- Taming OpenClaw: Security Analysis and Mitigation of Autonomous LLM Agent Threats
- Don't Let the Claw Grip Your Hand: A Security Analysis and Defense Framework for OpenClaw
- A Security Analysis of the OpenClaw AI Agent Framework
- Organizing, Orchestrating, and Benchmarking Agent Skills at Ecosystem Scale
- How Well Do Agentic Skills Work in the Wild: Benchmarking LLM Skill Usage in Realistic Settings
- SkillsBench: Benchmarking How Well Agent Skills Work Across Diverse Tasks
- ClawHub Security Signals: When VirusTotal, Static Analysis, and SkillSpector Disagree
Related papers
- Falsification-Based Verification of LLM-Generated Optimization Models: Sound Test Batteries and Their Detection Limits
- GitSkills: A Dataset of Agent Skills on GitHub
- SABER: Benchmarking Operational Safety of LLM Coding Agents in Stateful Project Workspaces
- PackMonitor: Enabling Zero Package Hallucinations Through Decoding-Time Monitoring
- IntentCoding: Amplifying User Intent in Code Generation
- Incentives and Outcomes in Bug Bounties