Marketplace security/Mar 26, 2026/7 min read
ClawHub vulnerability made trust the attack surface
Silverfort says an exposed public Convex mutation let anyone fake ClawHub downloads, push a malicious skill to the top, and turn OpenClaw trust into a supply-chain risk.

