Declawed: An Advanced Community-Driven Malware Scanner for ClawHub SKILL.md Files

Declawed is a security tool designed to scan SKILL.md files uploaded to ClawHub. It focuses on detecting malicious content including prompt injection, info stealers, and other threats within markdown files. The project emerged in response to a rise in malicious content being introduced into the ClawHub ecosystem.
Initially attempting to compete with OpenClaw's partnership with VirusTotal, Declawed showcases superior detection capabilities for advanced threat payloads. This is achieved through novel prompt injection detection and ascii smuggling techniques, which outperformed those of VirusTotal in certain tests.
Central to Declawed's effectiveness is its community-driven nature. It utilizes YAML files to allow users to build and expand the detection rulesets dynamically, catering to the continually evolving landscape of AI and cyber threats. Additionally, the platform supports agent-driven workflows alongside regular user interactions, with functionalities allowing agents and humans to comment and vote on scan results. A unique reverse-captcha system ensures proper registration distinguishing between human and agent registrants.
Additional features include the integration of STIX and TAXII standards to support threat intelligence feeds, offering companies a mechanism to integrate this intelligence with their Security Information Event Management (SIEM) and Extended Detection and Response (XDR) tools.
📖 Read the full source: r/openclaw
👀 See Also

U of T Researchers Demonstrate AI Worm Powerable by Free Open-Weight Models
Researchers at the University of Toronto demonstrated the first AI-powered worm that adapts its spreading strategy using publicly accessible open-weight models, targeting any online device.

Security Warning: ClawProxy Script Stole API Keys, Resulting in Significant OpenRouter Bill
A developer installed a closed-source ClawProxy script from a Reddit user on a sandboxed WSL Ubuntu 24.04 system, which stole their OpenRouter API key and used it via Google Vertex API to run up a large bill on Opus 4.6 overnight.

OpenClaw Security Hardening: Multi-Layered Protection Against Autonomous Agent Risks
A developer modified OpenClaw's codebase to add a multi-layered security stack including a hard-deny regex guard, recursive de-obfuscator, AppArmor profile, and audit integration to prevent destructive commands and data exfiltration by autonomous agents.

AI Chatbots Leaking Real Phone Numbers: The PII Exposure Problem
Chatbots like Gemini, ChatGPT, and Claude are exposing real personal phone numbers due to PII in training data. DeleteMe reports a 400% increase in AI-related privacy requests in seven months.