OpenClaw partners with VirusTotal and says that all skills published to ClawHub are now scanned using VirusTotal's threat intelligence
Artificial Intelligence / Vulnerability — OpenClaw (formerly Moltbot and Clawdbot) has announced that it's partnering with Google-owned VirusTotal …
Context & Ripple Effects
ClawHub's security posture has become a central issue after a report identified more than 230 malicious extensions uploaded to the marketplace since late January. The VirusTotal integration is a concrete response aimed at the distribution layer rather than individual users alone.
The change also arrives as the project settles under the OpenClaw name after earlier rebrands, making marketplace trust important to the continuity of its developer ecosystem.
First-order effects
- Skills submitted to ClawHub are now subject to VirusTotal threat-intelligence scanning, giving OpenClaw an automated screening layer at publication.
- Skill publishers and ClawHub users face a marketplace with more visible security controls, though scanning does not by itself establish that every skill is safe.
Second-order effects
- The prior malicious-extension reports raise the cost of distributing obvious malware through ClawHub and may push attackers toward evasion techniques or less-policed distribution channels.
- Other AI-agent skill marketplaces will face stronger pressure to offer comparable submission screening and explain how they handle flagged packages.
Third-order effects
- If maintained and paired with effective enforcement, security scanning could become baseline marketplace infrastructure for agent extensions, much as discovery and hosting already are.
- The episode highlights a structural tension in agent ecosystems: open, fast-growing skill catalogs need centralized trust controls, potentially increasing reliance on specialist threat-intelligence providers.
The trend: AI-agent marketplaces are moving from open extension distribution toward platform-managed security and provenance controls as malicious skills emerge.