OpenClaw says every skill and plugin uploaded to ClawHub now gets an additional security review from Tencent’s AI-Infra-Guard, alongside NVIDIA’s SkillSpector. The change puts automated checks into the marketplace’s upload review, where a risky plugin can otherwise become someone’s very avoidable afternoon.
OpenClaw Watch analysis
What happened
OpenClaw says it has integrated Tencent’s AI-Infra-Guard (AIG) into ClawScan, the open-source tool used for ClawHub security reviews. The two scanners run independently, and an AI judge assesses their findings alongside the uploaded files. OpenClaw says this allows the scanners’ different assessments to inform a final security review.
In a 556-case subset of the SkillTrustBench benchmark, OpenClaw says the combined system matched 86.9% of the benchmark’s labels and correctly classified 98.6% of malicious cases. Those figures describe the benchmark evaluation, not a guarantee that every harmful skill will be caught. Read OpenClaw’s announcement.
Why it matters
ClawHub skills and plugins can bring code, dependencies and instructions into an agent’s environment. OpenClaw says AIG reviews nine categories of risk, including instruction hijacking, memory poisoning, remote payload execution and insecure dependencies. That gives upload reviews a broader set of checks, while the benchmark figures offer a concrete, if bounded, account of how the combined system performed.
OpenClaw also says it shares anonymised cases where the scanners disagree, plus confirmed false positives, with Tencent for regression tests and improvements. The useful detail is not simply that another scanner has joined the queue: the companies say those disagreements feed back into testing and development.
Our read
This is a practical security improvement for a marketplace built around extensions that can influence an AI agent’s behaviour. Running two scanners independently is a sensible way to surface different risks; the next test is whether that translates into dependable reviews of real submissions. Benchmark accuracy is a useful measure, not a safety certificate. Plugins, regrettably, do not come with one.
What to watch
- Whether OpenClaw publishes results from ongoing ClawHub reviews, not just the fixed benchmark subset.
- How the system handles disagreement between AIG and SkillSpector, including false positives.
- Whether contributors can inspect or reproduce the benchmark and review process.
Discussion spark: Should an AI-agent marketplace require two independent security scanners for every plugin, or is a well-tested single scanner enough?
Sources and evidence
- Source update (2 October 2026, 00:00 UTC)
OpenClaw Watch is independently operated by WittyWires. It is not affiliated with, endorsed by, or operated by the OpenClaw Foundation.