- Published on
ClawHub Skills: How to Install Without Getting Compromised
341 malicious skills were discovered on ClawHub in February 2026 distributing macOS infostealing malware. Here's exactly how to review any skill before you install it.

Tested on a live 24/7 production agent. Updated regularly.
Organize your OpenClaw projects using Telegram groups. Create groups, get their IDs, and your agent handles the rest. See project status at a glance.
Fix OpenClaw Telegram errors fast: 401 unauthorized, allowFrom config, group pairing, silent bots, and chat ID problems with actual commands.
Learn OpenClaw cron jobs with three schedule types, real examples, and common mistakes. Automate your AI agent while you sleep.
A biweekly newsletter recapping new articles, OpenClaw updates, and what we are building.
Get new posts in your inbox.
341 malicious skills were discovered on ClawHub in February 2026 distributing macOS infostealing malware. Here's exactly how to review any skill before you install it.
Run openclaw security audit --deep to scan your instance for misconfigurations. Add --fix to auto-remediate what it can. This guide walks through every finding the tool reports and how to resolve the ones it can't fix automatically.
Five changes lock down an OpenClaw instance: bind to localhost, set auth token, configure allowlists, review tool permissions, run security audit. Three tiers.
Fix the OpenClaw gateway connect pairing required error with 6 step-by-step solutions for missing scopes, token mismatches, and port conflicts.
Gemini 3.1 Pro scores 2887 Elo on LiveCodeBench and 80.6% on SWE-Bench at $2/$12 per million tokens. Where it leads and where it falls short.
Two prompts you paste into AGENTS.md that survive OpenClaw compaction. Tested across dozens of cycles on a 24/7 production agent.
Godot maintainers are buried under AI-generated pull requests. They are not alone. Here is what is happening and what is being done.
Fix OpenClaw BlueBubbles errors: plugin not found, 401 auth failures, ECONNREFUSED, missing webhook events, tapback issues, and macOS permission errors.