AI security firm SentinelOne released a timely solution that hardens agentic deployments against supply chain attacks and prompt injections.
Claimed to be the first open-source security suite of its sort, the ClawSec tool specifically tackles deployments of OpenClaw, a lobster-themed system that lets AI agents automatically call, coordinate, and delegate tasks with each other. Previously known as Clawdbot and Moltbot, the much-hyped system uses model context protocol (MCP) to let agents manages inboxes, calendars, and other administrative tasks for humans across WhatsApp and other apps.
In its launch of the service, SentinelOne pointed to the discovery of more than 200 malicious OpenClaw skills last week, when use of the tool began to take off exponentially. This is down to how AI agents frequently download and run third-party skills without performing cryptographic verification or validation checks, a practice exacerbated by agent-to-agent pyramid schemes triggered in OpenClaw's wake, where AI agents talk to and trigger other agents to generate activity and fees, instead of delivering real work.
"Distributed through GitHub and OpenClaw’s official registry, these skills harvested API keys, cloud secrets, wallet data, and SSH credentials, highlighting how easily agent supply chains can be weaponized at scale," SentinelOne wrote. "This activity did not emerge in isolation. OpenClaw’s rapid growth, decentralized skill ecosystem, and deep system-level access have created a large, largely unmanaged attack surface. Skills are often installed directly from public repositories, documentation is trusted at face value, and agents are granted persistent memory and tool access that rivals traditional applications without equivalent security controls."
With the assumption blind trust "no longer holds" in today’s security landscape, ClawSec has been released on GitHub to operate as a “skill-of-skills” protection layer, enclosing agents within a continuously verified security framework that ensures proper execution, monitors system changes, and enforces data flow restrictions. ClawSec essentially, therefore, acts as a closed feedback loop security ecosystem where, once installed and activated, agents continuously detect threats, request decisions for verified reporting, and transform confirmed detections into shared protections that strengthen the entire network over time.
SentinelOne explained every security skill is distributed with verified sources and checksum validation, which acts as a file's digital fingerprint. To ensure full compatibility with all existing OpenClaw workflows, the suite supports both standard SKILL.md definitions, human-readable Markdown files that describe what a skill does and how it should behave, as well as packaged .skill formats, which are ready-to-run, machine-readable skill bundles.
Once deployed, it continuously monitors essential assets such as TOOLS.md, a Markdown file that lists and documents the tools an agent is allowed to use, as well as prompt baselines and configuration manifests for any signs of drift or tampering, alerting the agent immediately upon detection.
ClawSec also integrates a live, community-driven advisory feed powered by the National Vulnerability Database (NVD) and verified GitHub Issue submissions. When maintainers confirm a threat, it is published as an advisory accessible to all subscribed ClawSec agents.
Operating without a centralized server, ClawSec relies on GitHub workflows for updates, ensuring transparency, auditability, and resilience. As soon as a verified advisory is released, agents automatically respond by flagging compromised skills, warning users, and blocking execution paths associated with known vulnerabilities.
"As a deliberate design choice, ClawSec has a zero-trust stance on communication, enforcing silence as the baseline," SentinelOne explained. "Unauthorized egress and telemetry blocked outright, so the agent does not phone home when an anomaly, threat, or compromise is detected. Instead, it pauses and asks for explicit user consent before any reporting or external communications."
The tool leverages SentinelOne's acquisition last summer of shadow AI and agent safety tool Prompt Security, which took place after rumors Palo Alto Networks was looking to buy SentinelOne, in a deal that ultimately did not take place.
In a recent feature on AI safety on SDxCentral, Chris Hosking, AI and cloud security evangelist at SentinelOne, compared threat hunting in the current safety landscape to trying to find needles in a haystack, a process “exponentially accelerated with agentic AI,” according to the VP.
The threat posed by OpenClaw was also noted by Palo Alto Networks, who warned interconnection with AI agents isn’t necessarily secure and that such a level of ungoverned autonomy with agentic AI can give rise to “irreversible security incidents.”
Besides OpenClaw, so-called Reddit for AI agents Moltbook has also caused some cause for alarm, with SDxCentral discovering AI agents, some of whom operate on the OpenClaw system, sharing security evasion tips on the agent-exclusive – and also lobster-themed – forum, specifically on web scraping sites like X under the cover of mobile proxies. One agent in particular was found to be likely part of an OpenClaw agentic pyramid scheme, judging by its automated posts on social media.
That discovery saw Cloudflare suggest we are witnessing a more “mechanized evolution of the existing arms race.” That has not stopped the likes of Darktrace and Anthropic releasing tools to encourage agentic adoption with the added balm of safety guardrails for users.
Last week also saw Palo Alto Networks launch a portal to drive AI uptake among customers and partners, primarily by the use of vibe coding. Sachin Dharmapurikar, head of client technology at The Modern Data Company, warned last year that as part of the unsanctioned AI threat, vibe coding can lead to charts or insights generated with incomplete lineage or metadata, and then acted upon without verification.
“Unlike traditional shadow IT, vibe coding can embed inaccuracies deep into decision-making workflows. These AI-generated applications may appear to work correctly but contain significant flaws or vulnerabilities that non-technical users cannot identify,” Dharmapurikar explained.
Comments