OpenClaw partners with Google-owned VirusTotal and says that all skills on its ClawHub marketplace will now be scanned using VirusTotal's threat intelligence
Artificial Intelligence / Vulnerability — OpenClaw (formerly Moltbot and Clawdbot) has announced that it's partnering with Google-owned VirusTotal …
Context & Ripple Effects
OpenClaw's marketplace security move follows reports that more than 230 malicious extensions had been uploaded to ClawHub, often presented as crypto-trading tools. The partnership makes third-party threat intelligence part of the marketplace's publishing workflow.
The project had also just completed a second rebrand, from Clawdbot through Moltbot to OpenClaw. Adding a recognizable security partner gives the newly named marketplace a more concrete trust mechanism as it tries to stabilize its identity.
First-order effects
- Skills submitted to ClawHub are now scanned against VirusTotal threat intelligence, changing the immediate publication and review environment for skill publishers and prospective users.
- OpenClaw gains an external detection layer in response to the malicious-extension uploads, while VirusTotal becomes embedded in a marketplace security workflow.
Second-order effects
- Publishers of legitimate skills may need to address detections or false positives before users can confidently adopt their tools, raising the practical value of clean packaging and provenance.
- Other AI-agent extension marketplaces face stronger pressure to show comparable malware-screening controls, particularly where skills can be marketed as automation tools.
Third-order effects
- If marketplaces make threat scanning a default control, security screening is likely to become a baseline expectation for distributable AI-agent capabilities rather than an optional moderation feature.
- Detection partnerships can improve marketplace hygiene, but they do not by themselves establish whether a skill is safe in operation; durable trust will depend on how platforms handle findings and publisher accountability.
The trend: AI-agent ecosystems are moving from rapid, open extension distribution toward marketplace governance built around security scanning and trust signals.