{"schemaVersion":"guard-threat-campaign/v1","id":"HGTC-2026-CLAWHAVOC","slug":"clawhavoc-malicious-agent-skills","title":"ClawHavoc malicious agent skills","aliases":["ClawHavoc"],"summary":"Snyk documented a malicious agent-skills campaign in the ClawHub ecosystem that used plausible skill listings and installation prerequisites to deliver credential-stealing malware to AI-agent users.","status":"published","severity":"high","confidence":"high","uncertainty":"The public record establishes malicious skills and delivery behavior, but it does not establish the complete victim count or every downstream execution path. HOL does not independently attribute the actor.","firstObservedAt":"2026-02-02T00:00:00.000Z","lastObservedAt":"2026-02-05T00:00:00.000Z","publishedAt":"2026-08-09T11:30:00.000Z","reviewedAt":"2026-08-09T11:20:00.000Z","expiresAt":"2026-09-08T23:59:59.000Z","reviewer":"HOL Guard Research","sources":[{"id":"source:snyk-clawhavoc","label":"Snyk: ToxicSkills / ClawHavoc research","url":"https://snyk.io/blog/toxicskills-malicious-ai-agent-skills-clawhub/","sourceType":"other_primary","observedAt":"2026-08-09T11:20:00.000Z"}],"artifacts":[{"id":"artifact:clawhub-skills","artifactClass":"skill","ecosystem":"ClawHub","name":"reviewed malicious skill set","version":null,"defanged":true}],"indicators":[],"timeline":[{"id":"timeline:first-observed","occurredAt":"2026-02-02T00:00:00.000Z","eventType":"first_observed","summary":"ClawHavoc malicious agent skills was first observed in the reviewed source material.","sourceIds":["source:snyk-clawhavoc"]},{"id":"timeline:disclosure","occurredAt":"2026-02-05T00:00:00.000Z","eventType":"disclosure","summary":"The reviewed source published or updated its defensive analysis and remediation guidance.","sourceIds":["source:snyk-clawhavoc"]}],"coverage":[{"assertionId":"coverage:stable:claude-code","relationship":"partial","limitation":"The current stable manifest covers selected Claude Code action surfaces and skill/plugin artifacts, but it does not claim universal prevention of skill-driven social engineering or out-of-band execution."}],"policies":[{"policyId":"policy:agent-skill-onboarding-review","purpose":"Treat new or changed agent skills and instruction artifacts as untrusted until their contents, provenance, and requested capabilities are reviewed.","status":"available","limitation":"This policy reduces exposure on supported artifact and action surfaces; it cannot make arbitrary third-party instructions safe."}],"limitations":["Do not interpret this campaign record as a claim that Guard blocks every malicious skill or every instruction executed outside a supported harness boundary."],"correctionHref":"/guard/security/campaigns/clawhavoc-malicious-agent-skills/corrections"}