Home / Companies / Snyk / Blog / Post Details
Content Deep Dive

280+ Leaky Skills: How OpenClaw & ClawHub Are Exposing API Keys and PII

Blog post from Snyk

Post Details
Company
Date Published
Author
Luca Beurer-Kellner and Aleksei Kudrinskii and Marco Milanta and Kristian Bonde Nielsen and Hemang Sarkar and Liran Tal
Word Count
1,732
Company Posts That Month
19
Language
English
Hacker News Points
-
Post removed?
No
Summary

Snyk engineers uncovered significant security vulnerabilities within the ClawHub ecosystem, particularly in the handling of credentials by AI agent skills, which are crucial for the functionality of the OpenClaw personal AI assistant project. Utilizing the Evo Agent Security Analyzer, researchers found that approximately 7.1% of the skills, such as moltyverse-email and buy-anything, mishandle sensitive data like API keys and credit card information, embedding them in plaintext and making them vulnerable to exposure through Large Language Models (LLMs). These issues arise from improper developer practices, which treat AI agents like local scripts, leading to the potential leakage of sensitive data through conversation histories or output logs. Snyk highlights the need for AI Security Posture Management (AI-SPM) to mitigate these risks by assessing AI-native threats, implementing governance policies, and providing tools like mcp-scan to detect and remediate insecure agent skills and malicious behaviors.

Trends Found in this Post
Trend Post Mentions Total Month Mentions Posts Companies MoM
MCP 9 4,186 446 170 +13%
LLM 7 5,987 964 233 +29%
OpenClaw 7 1,515 119 48 +222%
AI Agents 4 4,369 971 249 +0%
Secrets Management 3 1,524 254 108 +20%
AI Coding Assistant 1 1,192 343 139 +32%
AI Guardrails 1 449 167 60 +25%
Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.