Skip to main content
Version: 1.0-draft | Framework: MITRE ATLAS (Adversarial Threat Landscape for AI Systems) + data flow diagrams This threat model documents adversarial threats to the OpenClaw AI agent platform and ClawHub skill marketplace. It is a living document maintained by the OpenClaw community. See Contributing to the threat model for how to report new threats, propose attack chains, or suggest mitigations. Key ATLAS resources: ATLAS website | ATLAS data and contribution guide

1. Scope

Out-of-scope reports and false-positive patterns (public internet exposure, prompt-injection-only chains without a boundary bypass, mutually untrusted operators sharing one gateway host, and others) are enumerated in SECURITY.md; that file is the current source of truth for vulnerability-report scope, not this page.

2. System architecture

2.1 Trust boundaries

2.2 Data flows


3. Threat analysis by ATLAS tactic

The threat catalog is split by ATLAS tactic. Each page below holds the full attribute table for every threat in that tactic. The risk matrix in section 5 and the recommendations summary in section 6 index across all of them, and the ATLAS technique mapping in section 7.1 lists which threats implement each technique.

4. ClawHub supply chain analysis

4.1 Current security controls

4.2 Moderation limitations

ClawHub’s static scanning inspects skill code content directly (not just slug/metadata/frontmatter), covering dangerous exec calls, dynamic code execution, credential harvesting, exfiltration patterns, obfuscated payloads, and more. Known gaps:
  • Pattern-based detection can still be bypassed by sufficiently novel obfuscation.
  • LLM-based review and VirusTotal scanning depend on operator-side API keys/config being enabled.
  • No runtime execution sandbox isolates a skill from the agent’s own privileges once installed.

4.3 Badges

Skills and packages carry moderator-assigned badges: highlighted, official, deprecated, redactionApproved (skills only). Community reporting (skillReports) and audit logging (auditLogs) back moderation workflows.

5. Risk matrix

5.1 Likelihood vs impact

5.2 Critical path attack chains

Chain 1: Skill-based data theft
Chain 2: Prompt injection to RCE
Chain 3: Indirect injection via fetched content

6. Recommendations summary

6.1 Immediate (P0)

6.2 Short-term (P1)

6.3 Medium-term (P2)


7. Appendices

7.1 ATLAS technique mapping

7.2 Key security files

7.3 Glossary


This threat model is a living document. Report security issues to security@openclaw.ai or see the Trust page.

Where each section moved

Every heading from the previous single-page version keeps its anchor here, so an existing link such as /security/THREAT-MODEL-ATLAS#t-exec-002-indirect-prompt-injection still resolves. Each entry points at the page that now holds the content.