OpenClaw AI Platform Faces Security Risks from Third-Party Extensions
- Certik’s report highlights significant security flaws in OpenClaw, an open-source AI platform.
- The platform’s reliance on “skill scanning” fails to protect users from malicious third-party extensions.
- Limitations were found in the Clawhub Moderation Pipeline, which is crucial for user protection.
Certik researchers have identified vulnerabilities in OpenClaw’s security measures, particularly concerning its ability to safeguard against harmful external extensions. These findings underscore the need for improved security protocols within the platform.
The report emphasizes that OpenClaw’s current “skill scanning” approach is inadequate in mitigating risks posed by third-party add-ons, highlighting a critical area for enhancement to ensure user safety. (Source)