AI RESEARCH

ClawHub Security Signals: When VirusTotal, Static Analysis, and SkillSpector Disagree

arXiv CS.AI

ArXi:2606.01494v1 Announce Type: cross Agent skills extend AI agents with reusable instructions, tools, scripts, references, and workflows, establishing a security boundary distinct from both model safety and traditional package-malware detection. ClawHub Security Signals is a sanitized dataset of 67,453 latest public OpenClaw skill versions. Each row pairs redacted SKILL.md content and sanitized bundled files where present with a final ClawScan registry verdict and evidence from three scanner families: VirusTotal, static heuristic analysis, and NVIDIA SkillSpector.