{
  "id": 3321,
  "url": "https://arxiv.org/abs/2606.01494v1",
  "title": "ClawHub Security Signals: When VirusTotal, Static Analysis, and SkillSpector Disagree",
  "summary": "Agent skills extend AI agents with reusable instructions, tools, scripts, references, and workflows, establishing a security boundary distinct from both model safety and traditional package-malware detection. ClawHub Security Signals is a sanitized dataset of 67,453 latest public OpenClaw skill versions. Each row pairs redacted SKILL.md content and sanitized bundled files where present with a final ClawScan registry verdict and evidence from three scanner families: VirusTotal, static heuristic a",
  "authors": "Vincent Koc, Patrick Erichsen, Jacob Tomlinson, Agustin Rivera, Michael Appel, Nir Paz",
  "category": "research",
  "topics": "agents-autonomy",
  "orgs": null,
  "regions": null,
  "published_at": "2026-05-31T23:20:25.000Z",
  "fetched_at": "2026-07-14T16:30:09.961Z",
  "source_slug": "arxiv-ethics",
  "source_name": "arXiv",
  "source_homepage": "https://arxiv.org",
  "ethics_ai_record_url": "https://ethics.ai/record/3321",
  "original_url": "https://arxiv.org/abs/2606.01494v1",
  "evidence_status": "source-only",
  "attribution": "via ethics.ai"
}