Security scan reveals high severity finding in AI agent find-skills tool

The find-skills tool, designed to help AI agents discover and install additional capabilities, has been flagged with a high severity security finding during a routine security scan.
What happened
A developer building out their AI agent setup used the find-skills tool to locate and install more skills. After installation, they ran a security scan on their entire setup and discovered that the find-skills tool itself returned a high severity security finding.
The developer noted: "The tool I used to find tools is the one I should've been worried about." This discovery prompted questions about overall ecosystem safety, with the developer asking: "Is anything even safe in this ecosystem?"
Key details from the source
- The developer had been building their AI agent setup for several weeks
- They used find-skills specifically to locate and install additional skills
- A security scan was performed after installation "out of mild paranoia"
- The scan revealed a high severity finding in the find-skills tool itself
- The finding raises questions about trust in the broader AI agent ecosystem
This incident highlights the importance of security practices even for tools designed to enhance functionality. When using tools that install or modify your AI agent setup, consider running security scans before and after installation to identify potential vulnerabilities.
📖 Read the full source: r/openclaw
👀 See Also

OpenClaw Patches Critical Privilege Escalation in /pair Approve Path
OpenClaw 2026.3.28 fixes a critical security vulnerability (GHSA-hc5h-pmr3-3497) where the /pair approve command allowed users with pairing privileges to approve device requests for broader scopes, including admin access. Affected versions are <= 2026.3.24.

Two Approaches to Reduce Data Leak Risk with AI Agents
A Reddit post outlines two methods for developers to control where their AI agent data goes: using your own API keys directly with providers like OpenAI or Anthropic to cut out middlemen, or running open-source models locally with tools like Ollama and OpenClaw.

Malicious PyTorch Lightning Package Steals Credentials and Worms npm Packages
PyPI package 'lightning' versions 2.6.2 and 2.6.3 contain Shai-Hulud themed malware that steals credentials, tokens, and cloud secrets, and spreads to npm packages via injected JavaScript payloads.

OpenClaw Security Alert: 500,000 Public Instances, Default Config Exposes Systems
A security analysis reveals 500,000 OpenClaw instances are publicly accessible, with 30,000 having known security risks and 15,000 exploitable through known vulnerabilities. The default installation disables authentication and binds to 0.0.0.0, exposing agent setups to the open internet.