TL;DR: A public skill registry flaw let an attacker inflate a malicious skill to the top of ClawHub, leading to 3,900 executions in six days across 50 cities and demonstrating how trust signals can be manipulated, according to Silverfort. Popularity-based ranking is not a security control when autonomous agents can discover and install code on behalf of users.
Editorial analysis by NHI Mgmt Group, based on content published by Silverfort: “Hijacking trust: ClawHub vulnerability enables attackers to manipulate rankings to become the #1 skill”.
By the numbers:
- In the proof of concept, the malicious skill reached 3,900 skill executions within 6 days across over 50 different cities.
Key questions
Q: What breaks when skill rankings can be manipulated in an agent marketplace?
A: Trust breaks first, because ranking becomes a proxy for legitimacy even when the underlying package has not been vetted.
Q: Why do autonomous agents make public skill registries harder to secure?
A: Because autonomous agents can act on scoring and metadata without the contextual skepticism a human might apply.
Q: What should teams look for in backend functions that alter trust signals?
A: Any public function that changes counters, rankings, or reputation data should be treated as security-sensitive.
Practitioner guidance
- Harden skill intake as a security gate Require every agent-installed skill to pass a pre-install inspection that checks package content, scripts, permissions, and metadata before any execution is allowed.
- Separate trust signals from install decisions Do not allow download counts, ranking scores, or popularity metrics to determine whether a skill is approved for use by an agent or human operator.
- Audit public backend functions Review all externally callable RPC endpoints and confirm that functions affecting counters, metadata, or other trust indicators require explicit authorization and input validation.
Bottom line: The core failure is not only a malicious skill, but the ability to inflate trust signals that make the skill look safe enough to install.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Popularity is not a security control when selection is delegated to agents. Download counts, scores, and search placement can influence both humans and autonomous agents, but they do not prove integrity, safety, or intended behaviour. In agentic supply chains, a manipulated trust signal is operationally equivalent to a compromised one, because it shapes what gets installed. Practitioners should stop treating marketplace popularity as evidence of trustworthiness.
A few things that frame the scale:
- The blast radius of the Salesloft-Drift OAuth supply chain attack was 10 times greater than earlier incidents in which attackers breached Salesforce directly.
A question worth separating out:
Q: Should security teams trust popularity metrics when approving agent tools?
A: No. Popularity can help with discovery, but it cannot establish code integrity, safe behaviour, or correct provenance. Approval decisions should rely on policy checks, package inspection, and controlled install flows rather than on social proof alone.
👉 Read our full editorial: OpenClaw skill ranking abuse exposes agentic supply chain risk