Security researchers have identified multiple malicious skills distributed through OpenClaw, an AI agent skill marketplace, including at least two macOS infostealers. The findings are a concrete demonstration of a threat that security professionals have been flagging in the abstract for months: the plugin and extension model that enterprise AI platforms are rapidly adopting carries the same structural vulnerabilities that made browser extension stores and IDE plugin repositories dangerous — and the industry has not learned the lessons the hard way enough times yet.
What Was Found
The malicious OpenClaw skills discovered include tools designed to exfiltrate data from macOS systems — infostealers that, when installed as agent capabilities, can quietly harvest credentials, files, and system information. The skills were publicly available online, meaning any user or organization deploying an OpenClaw-compatible agent could have installed them without obvious indication of malicious intent.
The specifics matter here. These are not theoretical proofs of concept. They are functional, deployed malware dressed as legitimate AI agent extensions. The packaging as a “skill” — a discrete, functional unit that extends what an AI agent can do — is precisely what makes them dangerous. Skills are designed to be trusted, installed quickly, and granted access to system resources by definition.
A Familiar Pattern in a New Wrapper
The browser extension ecosystem spent years learning this lesson, often at significant cost. The Chrome Web Store, Firefox Add-ons, and Visual Studio Code’s extension marketplace have all been vectors for credential theft, cryptomining, and data exfiltration campaigns. The attack model is consistent: publish something that looks useful, get it installed, and abuse the permissions the host environment grants.
AI agent skill marketplaces are structurally identical. A skill is a packaged capability — often with access to file systems, network connections, APIs, and in some configurations, the ability to invoke other tools or agents. The permissions surface is, in many cases, broader than a browser extension. An agent skill that can read files, make HTTP requests, and interact with local applications has significant reach on any system where it runs.
The difference in the current moment is that the security community’s institutional knowledge about extension ecosystem risks has not fully transferred to the teams building and deploying AI agent infrastructure. The tooling for vetting, sandboxing, and monitoring agent skills is nascent at best. Enterprise security policies rarely address third-party AI skills explicitly.
Why Enterprise AI Deployments Are Exposed
Most organizations deploying AI agents are focused on capability and productivity. The security conversation, where it exists, tends to center on data privacy and model outputs — prompt injection risks, data leakage through model APIs, and compliance with data residency requirements. The supply chain risk posed by third-party skills and plugins sits in a gap between application security and endpoint security teams, and it is frequently owned by neither.
Several structural factors compound the problem. First, skill marketplaces are growing faster than vetting processes. The incentive for platform operators is to maximize the number of available skills; rigorous security review slows that down. Second, enterprises often lack the visibility to know which skills are installed across their agent deployments, particularly in distributed or developer-led adoption scenarios. Third, the trust model for agent skills is often implicit — if a skill is available in an official or semi-official marketplace, users assume some level of vetting has occurred.
That assumption is demonstrably wrong.
The Infostealer Angle Is Particularly Significant
Infostealers represent one of the most commercially viable categories of malware in the current threat landscape. Stolen credentials harvested by infostealers feed a robust underground economy — they are used directly for account takeover, sold in bulk on criminal marketplaces, and leveraged for initial access in ransomware operations. The targeting of macOS is notable given the platform’s growing presence in enterprise environments, particularly among developers and technical staff who are also the most likely early adopters of AI agent tooling.
An infostealer embedded in an AI agent skill has a meaningful advantage over traditional delivery mechanisms: it operates in a context where broad system access is expected and where users are actively granting permissions as part of normal workflow. Behavioral anomalies that might flag a suspicious process on an endpoint are harder to distinguish from legitimate agent activity.
What Organizations Should Do Now
- Audit all AI agent skill installations across the organization and establish an approved list before expanding deployments further.
- Treat third-party AI skills with the same scrutiny applied to third-party software packages — verify sources, review permissions requested, and monitor behavior post-installation.
- Ensure endpoint detection and response tooling is configured to monitor processes spawned by AI agent runtimes, not just traditional application categories.
- Engage security teams early in any AI agent platform evaluation, specifically asking vendors what controls exist for skill vetting and sandboxing.
- Where possible, prefer self-hosted or enterprise-managed skill repositories over public marketplaces until the ecosystem matures.
The Broader Implication
The OpenClaw findings are unlikely to be isolated. Every AI agent platform with a third-party skill or plugin ecosystem — and there are now many — is a potential target for this attack pattern. Threat actors are adaptive, and the AI tooling space has grown too large and too quickly for security infrastructure to keep pace.
The history of extension ecosystems suggests the industry will eventually respond with better automated scanning, tighter permission models, and improved sandboxing. But that maturation takes time, and organizations deploying agent-based AI workflows today are operating in the gap between platform ambition and platform security. The malicious OpenClaw skills found this week are a signal that the exploitation phase has already begun.
Related InsightTrack Analysis
- AI Agent Orchestration Frameworks for Workflow Automation
- Agentic AI Benefits and Risks for Canadian Enterprises
- Local AI Deployment in Canada: Business Benefits
Source
Multiple malicious OpenClaw skills found online – including two macOS infostealers | TechRadar

