Claim this agent
agentCLAWHUBUnverified

clawsec-feed

Security advisory feed with automated NVD CVE polling for OpenClaw-related vulnerabilities. Updated daily. Skill: clawsec-feed Owner: davida-ps Summary: Security advisory feed with automated NVD CVE polling for OpenClaw-related vulnerabilities. Updated daily. Tags: latest:0.0.4 Version history: v0.0.4 | 2026-02-05T22:54:48.184Z | user Release 0.0.4 via CI v0.0.3 | 2026-02-05T22:37:11.473Z | user Release 0.0.3 via CI v0.0.2 | 2026-02-05T22:32:38.186Z | user Release 0.0.2 via CI v0.0.1 | 2026-02-05T21:14:52.097Z | user Rele

OpenClaw

Rank

62

Safety

84

Downloads

1.5k

Updated

Apr 15, 2026

Version

0.0.4

Source

CLAWHUB

About

What it does, and when to use it.

Capability contract not published. No trust telemetry is available yet. 1.5K downloads reported by the source. Last updated 4/15/2026.

Avoid when

  • Contract metadata is missing or unavailable for deterministic execution.

Risk flags: missing_or_unavailable_contract, trust_data_unavailable, schema_references_missing

Public facts

Every fact links back to the source it came from.

Vendor
Clawhubvendor · observed Apr 15, 2026
Protocol compatibility
OpenClawcompatibility · observed Apr 15, 2026
Adoption signal
1.5K downloadsadoption · observed Apr 15, 2026
Latest release
0.0.4release · observed Feb 5, 2026
Handshake status
UNKNOWNsecurity

Install and run

Setup complexity: low.

clawhub skill install kn76m78f01hqrtpgm895s0jsax80jd8v:clawsec-feed
  1. Setup complexity is LOW. This package is likely designed for quick installation with minimal external side-effects.
  2. Final validation: Expose the agent to a mock request payload inside a sandbox and trace the network egress before allowing access to real customer data.

Contract: missing

curl -s "https://www.xpersona.co/api/v1/agents/clawhub-davida-ps-clawsec-feed/snapshot"

Documentation

CLAWHUB

61,228 characters of source documentation, loaded on request.

Extracted files

5 files captured from the source.

SKILL.md

---
name: clawsec-feed
version: 0.0.4
description: Security advisory feed with automated NVD CVE polling for OpenClaw-related vulnerabilities. Updated daily.
homepage: https://clawsec.prompt.security
metadata: {"openclaw":{"emoji":"📡","category":"security"}}
clawdis:
  emoji: "📡"
  requires:
    bins: [curl, jq]
---

# ClawSec Feed 📡

Security advisory feed monitoring for AI agents. Subscribe to community-driven threat intelligence and stay informed about emerging threats.

This feed is automatically updated daily with CVEs related to OpenClaw, clawdbot, and Moltbot from the NIST National Vulnerability Database (NVD).

**An open source project by [Prompt Security](https://prompt.security)**

---

## Installation Options

You can get clawsec-feed in two ways:

### Option A: Bundled with ClawSec Suite (Recommended)

**If you've installed clawsec-suite, you may already have this!**

ClawSec-feed is bundled alongside ClawSec Suite to provide crucial CVE and threat intelligence information. When you install the suite, if you don't already have the feed installed, it will be deployed from the bundled copy.

**Advantages:**
- Convenient - no separate download needed
- Standard location - installed to `~/.openclaw/skills/clawsec-feed/`
- Preserved - if you already have feed installed, it won't be overwritten
- Single verification - integrity checked as part of suite package

### Option B: Standalone Installation (This Page)

Install clawsec-feed independently without the full suite.

**When to use standalone:**
- You only need the advisory feed (not other suite components)
- You want to install before installing the suite
- You prefer explicit control over feed installation

**Advantages:**
- Lighter weight installation
- Independent from suite
- Direct control over installation process

Continue below for standalone installation instructions.

---

Installation Steps:
Agents should review scripts before execution!


```bash
# Get latest clawsec-feed release tag
LATEST_TAG=$(curl -sSL https://api.github.com/repos/prompt-security/ClawSec/releases | \
  jq -r '[.[] | select(.tag_name | startswith("clawsec-feed-v"))][0].tag_name')

# Download SKILL.md from latest release
SKILL_URL="https://github.com/prompt-security/clawsec/releases/download/$LATEST_TAG/SKILL.md"
curl -sSL --fail --show-error "$SKILL_URL"
```

Once you have this skill file, proceed to **[Deploy ClawSec Feed](#deploy-clawsec-feed)** below.

---

## Deploy ClawSec Feed

Installation steps:

### Step 1: Create skill directory and save this file

```bash
mkdir -p ~/.openclaw/skills/clawsec-feed
# Save this SKILL.md as SKILL.md in the directory above
```

### Step 2: Install skill files

```bash
# Get latest release tag with retry logic
LATEST_TAG=$(curl -sSL --retry 3 --retry-delay 1 \
  https://api.github.com/repos/prompt-security/ClawSec/releases | \
  jq -r '[.[] | select(.tag_name | startswith("clawsec-feed-v"))][0].tag_name')

BASE_URL="https://github.com/prompt-security/clawsec/release

README.md

# ClawSec Feed 📡

Security advisory feed monitoring for AI agents. Subscribe to community-driven threat intelligence and stay informed about emerging threats.

## Features

- **Real-time Advisories** - Get notified about malicious skills, vulnerabilities, and attack patterns
- **Cross-Reference Detection** - Automatically checks if your installed skills are affected
- **Community-Driven** - Advisories contributed and reviewed by the security community
- **Heartbeat Integration** - Seamlessly integrates with your agent's routine checks

## Quick Install

```bash
curl -sLO https://github.com/prompt-security/clawsec/releases/latest/download/clawsec-feed.skill
```

## Advisory Types

| Type | Description |
|------|-------------|
| `malicious_skill` | Skills identified as intentionally harmful |
| `vulnerable_skill` | Skills with security vulnerabilities |
| `prompt_injection` | Known prompt injection patterns |
| `attack_pattern` | Observed attack techniques |

## Feed Structure

```json
{
  "version": "1.0",
  "updated": "2026-02-02T12:00:00Z",
  "advisories": [
    {
      "id": "GA-2026-001",
      "severity": "critical",
      "type": "malicious_skill",
      "title": "Data exfiltration in 'helper-plus'",
      "affected": ["[email protected]"],
      "action": "Remove immediately"
    }
  ]
}
```

## Response Example

```
📡 ClawSec Feed: 2 new advisories

CRITICAL - GA-2026-015: Malicious prompt pattern
  → Update your system prompt defenses.

HIGH - GA-2026-016: Vulnerable skill "data-helper"
  → You have this installed! Update to v1.2.1
```

## Related Skills

- **openclaw-audit-watchdog** - Automated daily security audits
- **clawtributor** - Report vulnerabilities to the community

## License

MIT License - [Prompt Security](https://prompt.security)

_meta.json

{
  "ownerId": "kn76m78f01hqrtpgm895s0jsax80jd8v",
  "slug": "clawsec-feed",
  "version": "0.0.4",
  "publishedAt": 1770332088184
}

advisories/feed.json

{
  "version": "0.0.2",
  "updated": "2026-02-05T12:53:37Z",
  "description": "Community-driven security advisory feed for ClawSec. Automatically updated with OpenClaw-related CVEs from NVD and community-reported security incidents.",
  "advisories": [
    {
      "id": "CVE-2026-25475",
      "severity": "medium",
      "type": "vulnerable_skill",
      "title": "OpenClaw is a personal AI assistant. Prior to version 2026.1.30, the isValidMedia() function in src/...",
      "description": "OpenClaw is a personal AI assistant. Prior to version 2026.1.30, the isValidMedia() function in src/media/parse.ts allows arbitrary file paths including absolute paths, home directory paths, and directory traversal sequences. An agent can read any file on the system by outputting MEDIA:/path/to/file, exfiltrating sensitive data to the user/channel. This issue has been patched in version 2026.1.30.",
      "affected": [],
      "action": "Review and update affected components. See NVD for remediation details.",
      "published": "2026-02-04T20:16:07.287",
      "references": [
        "https://github.com/openclaw/openclaw/security/advisories/GHSA-r8g4-86fx-92mq"
      ],
      "cvss_score": 6.5,
      "nvd_url": "https://nvd.nist.gov/vuln/detail/CVE-2026-25475"
    },
    {
      "id": "CVE-2026-25157",
      "severity": "high",
      "type": "vulnerable_skill",
      "title": "OpenClaw is a personal AI assistant. Prior to version 2026.1.29, there is an OS command injection vu...",
      "description": "OpenClaw is a personal AI assistant. Prior to version 2026.1.29, there is an OS command injection vulnerability via the Project Root Path in sshNodeCommand. The sshNodeCommand function constructed a shell script without properly escaping the user-supplied project path in an error message. When the cd command failed, the unescaped path was interpolated directly into an echo statement, allowing arbitrary command execution on the remote SSH host. The parseSSHTarget function did not validate that SSH target strings could not begin with a dash. An attacker-supplied target like -oProxyCommand=... would be interpreted as an SSH configuration flag rather than a hostname, allowing arbitrary command execution on the local machine. This issue has been patched in version 2026.1.29.",
      "affected": [],
      "action": "Review and update affected components. See NVD for remediation details.",
      "published": "2026-02-04T20:16:06.577",
      "references": [
        "https://github.com/openclaw/openclaw/security/advisories/GHSA-q284-4pvr-m585"
      ],
      "cvss_score": 7.7,
      "nvd_url": "https://nvd.nist.gov/vuln/detail/CVE-2026-25157"
    },
    {
      "id": "CLAW-2026-0001",
      "severity": "high",
      "type": "prompt_injection",
      "title": "Data exfiltration attempt via helper-plus skill",
      "description": "The helper-plus skill was observed sending conversation data to an external server (suspicious-domain.com) on every invocation. The skill makes

skill.json

{
  "name": "clawsec-feed",
  "version": "0.0.4",
  "description": "Security advisory feed monitoring for AI agents. Subscribe to community-driven threat intelligence.",
  "author": "prompt-security",
  "license": "MIT",
  "homepage": "https://clawsec.prompt.security",
  "keywords": [
    "security",
    "advisory",
    "feed",
    "agents",
    "ai",
    "threat-intel",
    "monitoring"
  ],
  "sbom": {
    "files": [
      {
        "path": "SKILL.md",
        "required": true,
        "description": "Advisory feed skill documentation"
      },
      {
        "path": "advisories/feed.json",
        "required": true,
        "description": "Community security advisory feed"
      }
    ]
  },
  "openclaw": {
    "emoji": "📡",
    "category": "security",
    "feed_url": "https://api.github.com/repos/prompt-security/ClawSec/releases?skill=clawsec-feed",
    "requires": {
      "bins": [
        "curl",
        "jq"
      ]
    },
    "triggers": [
      "security advisories",
      "check advisories",
      "clawsec",
      "threat feed",
      "security alerts",
      "vulnerability feed",
      "advisory feed",
      "security news"
    ]
  }
}
Github ReposUpdated 1h agoRank 70

AionUi

Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!

MCPOPENCLAW
Github ReposUpdated 6mo agoRank 70

activepieces

AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents

OPENCLAW
Github ReposUpdated 6mo agoRank 70

cherry-studio

AI productivity studio with smart chat, autonomous agents, and 300+ assistants.

MCPOPENCLAW
Github ReposUpdated 7mo agoRank 70

CopilotKit

The Frontend for Agents & Generative UI. React + Angular

OPENCLAW

Machine-readable data

The same record, as JSON, for agents and crawlers.

{
  "facts": [
    {
      "factKey": "vendor",
      "category": "vendor",
      "label": "Vendor",
      "value": "Clawhub",
      "href": "https://clawhub.ai/davida-ps/clawsec-feed",
      "sourceUrl": "https://clawhub.ai/davida-ps/clawsec-feed",
      "sourceType": "profile",
      "confidence": "medium",
      "observedAt": "2026-04-15T00:45:39.800Z",
      "isPublic": true
    },
    {
      "factKey": "protocols",
      "category": "compatibility",
      "label": "Protocol compatibility",
      "value": "OpenClaw",
      "href": "https://www.xpersona.co/api/v1/agents/clawhub-davida-ps-clawsec-feed/contract",
      "sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-davida-ps-clawsec-feed/contract",
      "sourceType": "contract",
      "confidence": "medium",
      "observedAt": "2026-04-15T00:45:39.800Z",
      "isPublic": true
    },
    {
      "factKey": "traction",
      "category": "adoption",
      "label": "Adoption signal",
      "value": "1.5K downloads",
      "href": "https://clawhub.ai/davida-ps/clawsec-feed",
      "sourceUrl": "https://clawhub.ai/davida-ps/clawsec-feed",
      "sourceType": "profile",
      "confidence": "medium",
      "observedAt": "2026-04-15T00:45:39.800Z",
      "isPublic": true
    },
    {
      "factKey": "latest_release",
      "category": "release",
      "label": "Latest release",
      "value": "0.0.4",
      "href": "https://clawhub.ai/davida-ps/clawsec-feed",
      "sourceUrl": "https://clawhub.ai/davida-ps/clawsec-feed",
      "sourceType": "release",
      "confidence": "medium",
      "observedAt": "2026-02-05T22:54:48.184Z",
      "isPublic": true
    },
    {
      "factKey": "handshake_status",
      "category": "security",
      "label": "Handshake status",
      "value": "UNKNOWN",
      "href": "https://www.xpersona.co/api/v1/agents/clawhub-davida-ps-clawsec-feed/trust",
      "sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-davida-ps-clawsec-feed/trust",
      "sourceType": "trust",
      "confidence": "medium",
      "observedAt": null,
      "isPublic": true
    }
  ],
  "events": [
    {
      "eventType": "release",
      "title": "Release 0.0.4",
      "description": "Release 0.0.4 via CI",
      "href": "https://clawhub.ai/davida-ps/clawsec-feed",
      "sourceUrl": "https://clawhub.ai/davida-ps/clawsec-feed",
      "sourceType": "release",
      "confidence": "medium",
      "observedAt": "2026-02-05T22:54:48.184Z",
      "isPublic": true
    }
  ]
}

Record generated Oct 9, 2026.

Sponsored

Ads related to clawsec-feed and adjacent AI workflows.