ClawHub FAQ
Frequently Asked Questions about ClawHub, OpenClaw Skills, and Security
Run Your OpenClaw Agent 24/7
Stop managing servers. Let us host your OpenClaw agent with automatic updates, real-time monitoring, and instant scaling across all major messaging platforms.
Browse by Topic
General Questions
ClawHub is the official, centralized skill registry for OpenClaw, serving as the "npm for AI agents." It hosts 3,286 community-built skills that extend OpenClaw agent functionality.
ClawHub provides vector search, version control, and community features for discovering and managing skills. It's built and maintained by the OpenClaw project team.
Yes, ClawHub is completely free. All 3,286 OpenClaw skills are available at no cost. Both using and publishing skills is free for everyone.
There are no subscription fees, premium tiers, or hidden costs. ClawHub is an open platform for the OpenClaw community.
ClawHub is built and maintained by the official OpenClaw team, led by Peter Steinberger, with support from:
- Community moderators
- Security researchers
- Open-source contributors
As of February 2026, ClawHub hosts:
- 3,286 total community-built skills
- 1.5M+ total downloads
- 2,999 community star ratings
- 6,375 current active installations
Skills are organized into 11 major categories including AI/ML, Utility, Development, Productivity, and more.
The 11 main categories on ClawHub are:
- AI/ML (1,588 skills, 48.3%) - AI models, NLP, embeddings, RAG
- Utility (1,520 skills, 46.3%) - File operations, storage, system tools
- Development (976 skills, 29.7%) - GitHub, CI/CD, testing, databases
- Productivity (822 skills, 25.0%) - Document processing, scheduling, email
- Web (637 skills, 19.4%) - Browser automation, HTTP requests, web scraping
- Science (598 skills, 18.2%) - Data analysis, statistics, research tools
- Media (365 skills, 11.1%) - Video, audio, image processing, YouTube
- Social (364 skills, 11.1%) - Twitter, Discord, Slack, Telegram
- Finance (311 skills, 9.5%) - Stock analysis, cryptocurrency, investing
- Location (153 skills, 4.7%) - Maps, weather, navigation, travel
- Business (151 skills, 4.6%) - Marketing, CRM, enterprise tools
ClawHavoc Security Incident
In February 2026, a security audit discovered 341 malicious skills on ClawHub that contained Atomic Stealer malware designed to steal:
- User credentials and passwords
- Cryptocurrency wallets
- Sensitive personal data
The malicious skills used fake prerequisites to trick users into downloading malware. The OpenClaw team removed all affected skills within 24 hours and implemented enhanced security measures.
Read more: Complete Security Guide
Yes, ClawHub has implemented comprehensive security improvements:
- ✓ Automated malware scanning for all submissions
- ✓ Stricter review processes (2-5 business days)
- ✓ Enhanced community reporting system
- ✓ 3 independent reports automatically hide skills
- ✓ Real-time security monitoring
- ✓ Strengthened moderation team
However, users should always follow security best practices when installing skills. See our Best Practices Guide.
Follow these security practices:
- Review skills before installing - read documentation
- Check author reputation and verification status
- Read community comments and ratings
- Prefer skills with high star ratings and download counts
- Report suspicious behavior immediately
- Keep skills updated with latest security patches
- Read our Security Guide
If you installed any skills during the incident timeframe (early February 2026), review the list of malicious skills on our Security Guide page.
If you installed any affected skills:
- Uninstall the skill immediately
- Run malware scans on your system
- Change passwords for affected accounts
- Monitor for unusual activity
- Follow remediation steps in the Security Guide
Installation Questions
Use the OpenClaw CLI command:
openclaw skill install [skill-name]
# Install specific version
openclaw skill install [skill-name]@1.2.3
Example: openclaw skill install github-integration
See our Complete Installation Guide for detailed instructions.
No, OpenClaw only supports one version of each skill at a time. Installing a new version will replace the existing installation.
This design ensures consistency and prevents version conflicts within your OpenClaw agent environment.
No account is needed to browse and install skills.
You only need a ClawHub account (linked to GitHub) if you want to:
- Publish your own skills
- Star skills
- Leave comments and reviews
- Report issues
Note: To publish skills, your GitHub account must be at least one week old.
Common solutions:
- Check your internet connection
- Verify the skill name spelling
- Check for version conflicts with
openclaw skill outdated - Try with
--forceflag to reinstall - Review error messages for specific issues
- Check if the skill was removed from ClawHub
See our Troubleshooting Guide for detailed help.
Yes, you can download skill packages and install them locally:
However, initial skill downloads require an internet connection. You can download skills from ClawHub.ai as zip files for offline installation.
Skill Management
Use these commands to update skills:
openclaw skill update [skill-name]
# Update all skills
openclaw skill update --all
# Check for available updates
openclaw skill outdated
Best practice: Test updates in development environment before updating production skills.
Uninstall skills using:
openclaw skill remove [skill-name]
# Uninstall with dependencies
openclaw skill remove [skill-name] --cascade
# Clean up unused dependencies
openclaw skill prune
Run openclaw skill list to see all currently installed skills and their versions.
For detailed information about a specific skill, use openclaw skill info [skill-name].
No, skills do not auto-update. You must manually update them using the openclaw skill update command.
This gives you control over when updates are applied and allows you to test updates before deploying to production environments.
Publishing Skills
To publish a skill to ClawHub:
- Create a valid SKILL.md file with proper metadata
- Test your skill thoroughly
- Use
openclaw skill publishcommand - Your skill undergoes security review (2-5 business days)
- Once approved, it appears in the ClawHub directory
Requirements: GitHub account at least one week old
Yes, skills must meet these requirements:
- Valid SKILL.md file with proper metadata
- Clear and comprehensive documentation
- Proper semantic versioning (Semver)
- Pass security review and malware scanning
- Testing confirmation
- No malicious code or suspicious behavior
See the Publishing Guide for full requirements.
Review typically takes 2-5 business days, depending on skill complexity.
After the ClawHavoc incident, all skills undergo:
- Automated malware scanning
- Manual security review
- Code quality assessment
Security-sensitive skills may require additional review time.
Yes, use openclaw skill publish with an updated version number following Semver rules.
Updates also go through security review, but typically faster than initial publication. Make sure to update the version in your SKILL.md file.
Vector Search
Vector search uses embeddings (mathematical representations of meaning) to enable semantic skill discovery.
Instead of simple keyword matching, vector search understands the meaning and context of your search query.
Example: Searching "automate my emails" will find email automation skills even if they don't contain those exact words, because ClawHub understands the semantic meaning.
Vector search advantages:
- Understands meaning and context, not just keywords
- Finds relevant skills even without exact word matches
- Natural language queries work better
- Semantic understanding of skill functionality
- Better results for conceptual searches
Example: "help me organize tasks" finds task management skills, even if they use different terminology.
Yes, ClawHub supports both vector search (semantic) and traditional keyword search.
Use whichever works best for your needs. Vector search is recommended for natural language queries, while keyword search works well when you know exact skill names.
Version Control
ClawHub uses Semantic Versioning (Semver) in the format MAJOR.MINOR.PATCH (e.g., 1.2.3):
- MAJOR (1.0.0 → 2.0.0): Breaking changes, incompatible API
- MINOR (1.0.0 → 1.1.0): New features, backward compatible
- PATCH (1.0.0 → 1.0.1): Bug fixes, backward compatible
Use these version specifiers:
@1.2.3
# Compatible (allows 1.x.x)
@^1.2.0
# Patch updates only (allows 1.2.x)
@~1.2.0
# Latest version
@latest
OpenClaw will detect version conflicts and show warnings. To resolve:
- Update conflicting skills to compatible versions
- Choose specific versions manually
- Review dependency requirements
- Contact skill authors for compatibility updates
Use openclaw skill deps [skill-name] to view dependency tree.
Community
Report suspicious skills using:
- Use the "Report" button on the skill page at ClawHub.ai
- Email security issues to: [email protected]
- For critical security issues, follow responsible disclosure guidelines
Remember: 3 independent reports automatically hide a skill pending moderation review.
Yes! ClawHub is open-source. You can contribute via:
- GitHub repository: github.com/openclaw/clawhub
- Publishing your own skills (3,286 already available)
- Improving documentation
- Helping in community forums
- Reporting bugs and suggesting features
Users can star skills they find useful (similar to GitHub stars). Stars help others discover quality skills and indicate community approval.
Comments and reviews provide additional community feedback about skill quality, usability, and any issues.
Technical Questions
SKILL.md is the metadata file that defines a skill. It contains:
- Metadata: name, version, description, author
- Interface Definition: How AI agents call the skill's tools
- Execution Logic: Actual scripts (Python, Node.js, or Bash)
Every ClawHub skill must have a valid SKILL.md file.
Skills specify compatible OpenClaw versions in their SKILL.md file. Always check compatibility before installing.
Most skills work with recent OpenClaw versions, but major version updates may require skill updates.
Yes, ClawHub supports private skill registries for enterprise use.
Contact the OpenClaw team for enterprise setup options and private registry configuration.
Partial offline support:
- ✓ Basic skill management works offline if skills are already installed
- ✗ Skill discovery, installation, and updates require internet connection
- ✓ You can download skills as zip files for offline installation
About This Website
No, ClawHub.biz is an independent information portal. It is NOT officially affiliated with OpenClaw or ClawHub.
For official information, visit:
- Official ClawHub: https://clawhub.ai
- Official OpenClaw: https://openclaw.com
To provide comprehensive, user-friendly information about ClawHub and help users safely navigate the ecosystem, especially after the ClawHavoc security incident in February 2026.
This site aims to educate users about:
- Safe skill management practices
- Security best practices post-ClawHavoc
- How to use ClawHub effectively
- Understanding the OpenClaw skill ecosystem
Official ClawHub resources:
- Website: https://clawhub.ai
- Documentation: https://docs.openclaw.ai/tools/clawhub
- GitHub: https://github.com/openclaw/clawhub
- OpenClaw: https://openclaw.com
Still Have Questions?
For additional support and information, visit these resources: