We checked this claim: is it true that

OpenClaw released an open-source security tool that combines scanners from Nvidia, Cisco and Snyk to inspect community add-on software?

Confirmed

OpenClaw published the multi-scanner tool, but hackers bypassed its automated filters and researchers exposed a bug inside the scanner itself

AI Safety

OpenClaw adds scanner as security flaws mount

Software maker releases tool to check add-on files but researchers show hackers still bypass automated defenses

Published
NRB — News Republic Brigade

Other links

OpenClaw

In a nutshell

OpenClaw deployed an open-source scanner combining engines from Nvidia and Cisco to block malicious community add-ons from executing commands on user computers. The tool, called ClawScan, filters files submitted to the ClawHub marketplace, but researchers quickly bypassed its checks through file inflation and revealed a parsing vulnerability inside the scanner itself.

Highlights

  • OpenClaw packaged ClawScan inside Docker containers to run static checks and external engines from Nvidia and Cisco.
  • Security team Unit 42 found attackers evaded both ClawScan and VirusTotal by artificially inflating file sizes.
  • Researchers disclosed vulnerability CVE-2026-91835 in ClawScan's file parser, prompting the version 0.1.7 update.

From the Editor’s Diary

Automating code inspection creates a useful first filter, but static scanners cannot replace runtime boundaries when software add-ons hold unrestricted access to system commands.

Who's involved

  • OpenClaw

    Open-source software collective maintaining an automated assistant framework and an add-on store

    goal → Protecting its public catalog so community add-ons do not run rogue commands on member machines

  • ClawScan

    Standalone software tool running in isolated software containers to inspect agent code packages

    goal → Screening submitted programs through multiple security engines and enforcing install rules

  • Palo Alto Networks Unit 42

    Threat research arm of enterprise cybersecurity company Palo Alto Networks

    goal → Tracking software supply risks and showing how malicious files evade automated screening gates

  • Third-Party Scanner Vendors

    Technology firms, including Nvidia and Cisco, providing specialized analysis engines

    goal → Supplying code-checking models and security adapters to detect hidden attack patterns

In short

Software platform OpenClaw has put an automated security gate between community-built robot programs and user computers, attempting to stop rogue code before people run it.

The scanner makes a quick cat-and-mouse escalation between automated filters and evasion tricks the most likely next chapter for community software stores.

That arms race is likely because early scans miss simple bypasses, leaving human review and attacker techniques in constant tension.

How it unfolded

01

Technical tutorials warn of agent skill risks

2026-03-05 – 2026-03-05

Software guides cautioned that natural-language prompts and system access rights turn agent add-ons into severe security liabilities, urging users to vet files with early scanner tools.

1 source
02

Multi-scanner defenses face file inflation bypasses

2026-05-31 – 2026-06-23

OpenClaw attempted to harden its catalog by grouping several automated scanners together, but threat researchers showed how attackers evade those combined screens with basic packaging tricks.

2 sources
03

High-profile promotion collides with security bug

2026-09-14 – 2026-09-24

Developer promotion expanded the scanner's reach across the industry, but researchers quickly found a code-reading flaw in the tool itself that forced an immediate software update.

3 sources

Where things stand

ClawScan serves as the default security gate for the OpenClaw community catalog, distributed through standard developer registries and linked to external corporate scanning tools.

While version 0.1.7 eliminated a file-reading flaw inside the scanner, security researchers stress that artificial file padding and hidden prompt instructions keep defenses under pressure.

Sources

  • DataCampskill security overview · 2026-03-05
  • midudevecosystem bulletin · 2026-09-14