Reviewed threat campaign
ClawHavoc malicious agent skills
Snyk documented a malicious agent-skills campaign in the ClawHub ecosystem that used plausible skill listings and installation prerequisites to deliver credential-stealing malware to AI-agent users.
Uncertainty
The public record establishes malicious skills and delivery behavior, but it does not establish the complete victim count or every downstream execution path. HOL does not independently attribute the actor.
Limitations
- Do not interpret this campaign record as a claim that Guard blocks every malicious skill or every instruction executed outside a supported harness boundary.
Timeline
- · ClawHavoc malicious agent skills was first observed in the reviewed source material.
- · The reviewed source published or updated its defensive analysis and remediation guidance.
Publication clock: 4451.5 hours from reviewed disclosure timestamp to HOL publication; 24-hour high target; historical backfill outside target.
Guard coverage and non-coverage
- partial: coverage:stable:claude-code — The current stable manifest covers selected Claude Code action surfaces and skill/plugin artifacts, but it does not claim universal prevention of skill-driven social engineering or out-of-band execution.
Defensive policy guidance
- Treat new or changed agent skills and instruction artifacts as untrusted until their contents, provenance, and requested capabilities are reviewed.
Status: available. This policy reduces exposure on supported artifact and action surfaces; it cannot make arbitrary third-party instructions safe.
Sources
- Snyk: ToxicSkills / ClawHavoc research · observed 2026-08-09