This preprint presents a comprehensive, data-driven assessment of the OpenClaw autonomous AI agent ecosystem's security posture, synthesizing findings from 12+ security research organizations. We analyze four layers of the attack surface: (1) supply chain poisoning via the ClawHub skill marketplace (1,184+ confirmed malicious skills), (2) deployment misconfiguration and credential exposure (42,000+ internet-exposed instances, 93% with authentication bypass), (3) end-to-end exploitation paths including CVE-2026-25253 (CVSS 8.8), and (4) governance gaps in platform and institutional responses. We propose a four-dimensional threat model T=(D,U,C,M) extending Willison's "lethal trifecta" with persistent memory. Data sources include reports from Cisco, Trend Micro, Snyk, Bitdefender, Kaspersky, Microsoft, and Palo Alto Networks.
Gangyi Zhang (Wed,) studied this question.
Synapse has enriched 5 closely related papers on similar clinical questions. Consider them for comparative context: