ClawHub FAQ

Frequently Asked Questions about ClawHub, OpenClaw Skills, and Security

🤖
AiBotClaw.Com Official

Run Your OpenClaw Agent 24/7

Stop managing servers. Let us host your OpenClaw agent with automatic updates, real-time monitoring, and instant scaling across all major messaging platforms.

⚡ One-Click Setup 🔒 Auto Security 📱 WhatsApp/Telegram/Discord 📊 Real-time Stats
Starting at $16.99/mo Get Started

Browse by Topic

General Questions

What is ClawHub?

ClawHub is the official, centralized skill registry for OpenClaw, serving as the "npm for AI agents." It hosts 3,286 community-built skills that extend OpenClaw agent functionality.

ClawHub provides vector search, version control, and community features for discovering and managing skills. It's built and maintained by the OpenClaw project team.

Is ClawHub free to use?

Yes, ClawHub is completely free. All 3,286 OpenClaw skills are available at no cost. Both using and publishing skills is free for everyone.

There are no subscription fees, premium tiers, or hidden costs. ClawHub is an open platform for the OpenClaw community.

Who maintains ClawHub?

ClawHub is built and maintained by the official OpenClaw team, led by Peter Steinberger, with support from:

  • Community moderators
  • Security researchers
  • Open-source contributors
How many skills are available on ClawHub?

As of February 2026, ClawHub hosts:

  • 3,286 total community-built skills
  • 1.5M+ total downloads
  • 2,999 community star ratings
  • 6,375 current active installations

Skills are organized into 11 major categories including AI/ML, Utility, Development, Productivity, and more.

What are the main skill categories?

The 11 main categories on ClawHub are:

  • AI/ML (1,588 skills, 48.3%) - AI models, NLP, embeddings, RAG
  • Utility (1,520 skills, 46.3%) - File operations, storage, system tools
  • Development (976 skills, 29.7%) - GitHub, CI/CD, testing, databases
  • Productivity (822 skills, 25.0%) - Document processing, scheduling, email
  • Web (637 skills, 19.4%) - Browser automation, HTTP requests, web scraping
  • Science (598 skills, 18.2%) - Data analysis, statistics, research tools
  • Media (365 skills, 11.1%) - Video, audio, image processing, YouTube
  • Social (364 skills, 11.1%) - Twitter, Discord, Slack, Telegram
  • Finance (311 skills, 9.5%) - Stock analysis, cryptocurrency, investing
  • Location (153 skills, 4.7%) - Maps, weather, navigation, travel
  • Business (151 skills, 4.6%) - Marketing, CRM, enterprise tools

ClawHavoc Security Incident

What was the ClawHavoc incident?
⚠️ Security Incident - February 2026

In February 2026, a security audit discovered 341 malicious skills on ClawHub that contained Atomic Stealer malware designed to steal:

  • User credentials and passwords
  • Cryptocurrency wallets
  • Sensitive personal data

The malicious skills used fake prerequisites to trick users into downloading malware. The OpenClaw team removed all affected skills within 24 hours and implemented enhanced security measures.

Read more: Complete Security Guide

Is ClawHub safe now?

Yes, ClawHub has implemented comprehensive security improvements:

  • ✓ Automated malware scanning for all submissions
  • ✓ Stricter review processes (2-5 business days)
  • ✓ Enhanced community reporting system
  • ✓ 3 independent reports automatically hide skills
  • ✓ Real-time security monitoring
  • ✓ Strengthened moderation team

However, users should always follow security best practices when installing skills. See our Best Practices Guide.

How can I protect myself?

Follow these security practices:

  • Review skills before installing - read documentation
  • Check author reputation and verification status
  • Read community comments and ratings
  • Prefer skills with high star ratings and download counts
  • Report suspicious behavior immediately
  • Keep skills updated with latest security patches
  • Read our Security Guide
Were my systems affected by ClawHavoc?

If you installed any skills during the incident timeframe (early February 2026), review the list of malicious skills on our Security Guide page.

If you installed any affected skills:

  • Uninstall the skill immediately
  • Run malware scans on your system
  • Change passwords for affected accounts
  • Monitor for unusual activity
  • Follow remediation steps in the Security Guide

Installation Questions

How do I install a ClawHub skill?

Use the OpenClaw CLI command:

# Install latest version
openclaw skill install [skill-name]

# Install specific version
openclaw skill install [skill-name]@1.2.3

Example: openclaw skill install github-integration

See our Complete Installation Guide for detailed instructions.

Can I install multiple versions of the same skill?

No, OpenClaw only supports one version of each skill at a time. Installing a new version will replace the existing installation.

This design ensures consistency and prevents version conflicts within your OpenClaw agent environment.

Do I need a ClawHub account?

No account is needed to browse and install skills.

You only need a ClawHub account (linked to GitHub) if you want to:

  • Publish your own skills
  • Star skills
  • Leave comments and reviews
  • Report issues

Note: To publish skills, your GitHub account must be at least one week old.

What if a skill installation fails?

Common solutions:

  • Check your internet connection
  • Verify the skill name spelling
  • Check for version conflicts with openclaw skill outdated
  • Try with --force flag to reinstall
  • Review error messages for specific issues
  • Check if the skill was removed from ClawHub

See our Troubleshooting Guide for detailed help.

Can I install skills offline?

Yes, you can download skill packages and install them locally:

openclaw skill install ./path-to-skill.zip

However, initial skill downloads require an internet connection. You can download skills from ClawHub.ai as zip files for offline installation.

Skill Management

How do I update installed skills?

Use these commands to update skills:

# Update specific skill
openclaw skill update [skill-name]

# Update all skills
openclaw skill update --all

# Check for available updates
openclaw skill outdated

Best practice: Test updates in development environment before updating production skills.

How do I uninstall a skill?

Uninstall skills using:

# Uninstall single skill
openclaw skill remove [skill-name]

# Uninstall with dependencies
openclaw skill remove [skill-name] --cascade

# Clean up unused dependencies
openclaw skill prune
How can I see what skills are installed?

Run openclaw skill list to see all currently installed skills and their versions.

For detailed information about a specific skill, use openclaw skill info [skill-name].

Do skills update automatically?

No, skills do not auto-update. You must manually update them using the openclaw skill update command.

This gives you control over when updates are applied and allows you to test updates before deploying to production environments.

Publishing Skills

How do I publish my own skill?

To publish a skill to ClawHub:

  1. Create a valid SKILL.md file with proper metadata
  2. Test your skill thoroughly
  3. Use openclaw skill publish command
  4. Your skill undergoes security review (2-5 business days)
  5. Once approved, it appears in the ClawHub directory

Requirements: GitHub account at least one week old

Are there requirements for publishing?

Yes, skills must meet these requirements:

  • Valid SKILL.md file with proper metadata
  • Clear and comprehensive documentation
  • Proper semantic versioning (Semver)
  • Pass security review and malware scanning
  • Testing confirmation
  • No malicious code or suspicious behavior

See the Publishing Guide for full requirements.

How long does skill review take?

Review typically takes 2-5 business days, depending on skill complexity.

After the ClawHavoc incident, all skills undergo:

  • Automated malware scanning
  • Manual security review
  • Code quality assessment

Security-sensitive skills may require additional review time.

Can I update my published skill?

Yes, use openclaw skill publish with an updated version number following Semver rules.

Updates also go through security review, but typically faster than initial publication. Make sure to update the version in your SKILL.md file.

Vector Search

What is vector search?

Vector search uses embeddings (mathematical representations of meaning) to enable semantic skill discovery.

Instead of simple keyword matching, vector search understands the meaning and context of your search query.

Example: Searching "automate my emails" will find email automation skills even if they don't contain those exact words, because ClawHub understands the semantic meaning.

How is vector search better than keyword search?

Vector search advantages:

  • Understands meaning and context, not just keywords
  • Finds relevant skills even without exact word matches
  • Natural language queries work better
  • Semantic understanding of skill functionality
  • Better results for conceptual searches

Example: "help me organize tasks" finds task management skills, even if they use different terminology.

Can I still use traditional search?

Yes, ClawHub supports both vector search (semantic) and traditional keyword search.

Use whichever works best for your needs. Vector search is recommended for natural language queries, while keyword search works well when you know exact skill names.

Version Control

What versioning system does ClawHub use?

ClawHub uses Semantic Versioning (Semver) in the format MAJOR.MINOR.PATCH (e.g., 1.2.3):

  • MAJOR (1.0.0 → 2.0.0): Breaking changes, incompatible API
  • MINOR (1.0.0 → 1.1.0): New features, backward compatible
  • PATCH (1.0.0 → 1.0.1): Bug fixes, backward compatible
How do I specify version ranges?

Use these version specifiers:

# Exact version
@1.2.3

# Compatible (allows 1.x.x)
@^1.2.0

# Patch updates only (allows 1.2.x)
@~1.2.0

# Latest version
@latest
What if skills have conflicting versions?

OpenClaw will detect version conflicts and show warnings. To resolve:

  • Update conflicting skills to compatible versions
  • Choose specific versions manually
  • Review dependency requirements
  • Contact skill authors for compatibility updates

Use openclaw skill deps [skill-name] to view dependency tree.

Community

How do I report a malicious skill?

Report suspicious skills using:

  • Use the "Report" button on the skill page at ClawHub.ai
  • Email security issues to: [email protected]
  • For critical security issues, follow responsible disclosure guidelines

Remember: 3 independent reports automatically hide a skill pending moderation review.

Can I contribute to ClawHub development?

Yes! ClawHub is open-source. You can contribute via:

  • GitHub repository: github.com/openclaw/clawhub
  • Publishing your own skills (3,286 already available)
  • Improving documentation
  • Helping in community forums
  • Reporting bugs and suggesting features
How do stars and ratings work?

Users can star skills they find useful (similar to GitHub stars). Stars help others discover quality skills and indicate community approval.

Comments and reviews provide additional community feedback about skill quality, usability, and any issues.

Technical Questions

What is a SKILL.md file?

SKILL.md is the metadata file that defines a skill. It contains:

  • Metadata: name, version, description, author
  • Interface Definition: How AI agents call the skill's tools
  • Execution Logic: Actual scripts (Python, Node.js, or Bash)

Every ClawHub skill must have a valid SKILL.md file.

Are ClawHub skills compatible with all OpenClaw versions?

Skills specify compatible OpenClaw versions in their SKILL.md file. Always check compatibility before installing.

Most skills work with recent OpenClaw versions, but major version updates may require skill updates.

Can I use ClawHub with private/enterprise OpenClaw?

Yes, ClawHub supports private skill registries for enterprise use.

Contact the OpenClaw team for enterprise setup options and private registry configuration.

Does ClawHub work offline?

Partial offline support:

  • ✓ Basic skill management works offline if skills are already installed
  • ✗ Skill discovery, installation, and updates require internet connection
  • ✓ You can download skills as zip files for offline installation

About This Website

Is ClawHub.biz official?
⚠️ Important Disclaimer

No, ClawHub.biz is an independent information portal. It is NOT officially affiliated with OpenClaw or ClawHub.

For official information, visit:

Why was this site created?

To provide comprehensive, user-friendly information about ClawHub and help users safely navigate the ecosystem, especially after the ClawHavoc security incident in February 2026.

This site aims to educate users about:

  • Safe skill management practices
  • Security best practices post-ClawHavoc
  • How to use ClawHub effectively
  • Understanding the OpenClaw skill ecosystem
Where can I find official ClawHub?

Official ClawHub resources:

Still Have Questions?

For additional support and information, visit these resources: