ClawHub Moderation and Account Safety Guide

Learn how ClawHub handles reports, moderation holds, hidden listings, bans, and account standing. This guide is for users who need to understand safety enforcement on the marketplace.

Read this when

  • Reporting a skill, plugin, or package
  • Recovering from a held, hidden, or blocked listing
  • Understanding ClawHub moderation, bans, or account standing

Moderation and Account Safety

ClawHub permits publishing broadly, but public discovery and installation channels still require safeguards. Reporting mechanisms, moderation holds, hidden listings, and account enforcement help shield users when a release or account appears unsafe, deceptive, or noncompliant.

This document explains moderation and account status. For audit tags like Pass, Review, Warn, Malicious, and risk classification, refer to Security Audits.

Also consult Security and Acceptable usage. For copyright or other content rights matters, submit a request through Content Rights Requests.

Reports

Authenticated users can report skills, plugins, and packages.

Use ClawHub reports exclusively for unsafe marketplace content, for example:

  • malicious listings
  • misleading metadata
  • undeclared credentials or permission requirements
  • suspicious installation instructions
  • impersonation
  • bad-faith registrations or trademark misuse
  • content violating Acceptable usage

On a skill page, click the Report skill button. For packages, use the package reporting command or API.

Do not use ClawHub reports for vulnerabilities found in a third-party skill or plugin's own source code. Instead, report those directly to the publisher or the source repository linked from the listing. ClawHub does not maintain or patch third-party skill or plugin code.

GitHub Security Advisories for openclaw/clawhub target vulnerabilities in ClawHub itself. Examples include defects in the website, API, CLI, registry, authentication, scanning, moderation, or download/install trust boundaries. Do not use ClawHub advisories for vulnerabilities in third-party skills or plugins.

Effective reports are specific and actionable. Misusing the reporting system can itself lead to account enforcement.

Org and namespace claims

For disputes over org, brand, package-scope, owner-handle, or namespace ownership, use the Org and Namespace Claims process rather than the in-product report flow or the account appeal form.

Use that process when you need ClawHub staff to examine non-sensitive evidence that a namespace should be reserved, transferred, renamed, hidden, quarantined, aliased, or otherwise reviewed. Do not include secrets, private documents, private legal files, personal identity documents, API tokens, or DNS challenge tokens in a public issue.

Moderation holds

Certain severe findings or policy violations may place a publisher or listing under a moderation hold. In such cases, affected content might be hidden from public discovery, or future publishes may start hidden until the issue is reviewed.

Moderation holds aim to protect users while ClawHub resolves high-risk situations. They can also be lifted when a false positive is confirmed.

Hidden or blocked listings

A listing may be held, hidden, quarantined, revoked, or otherwise unavailable on public installation surfaces.

If you encounter one of these states, do not install the release unless the owner resolves the issue or moderation restores it.

Owners can still view diagnostics for their own held or hidden listings. These diagnostics clarify what occurred and what must change before the listing can reappear on public surfaces.

Bans and account standing

Accounts violating ClawHub policy may lose publishing privileges. Severe abuse can lead to account bans, token revocation, hidden content, or removed listings. Publisher abuse pressure signals are evaluated daily. Signals reaching ClawHub's potential-ban threshold can trigger an automatic warning. If the next eligible scan after the warning deadline still places the publisher in the potential-ban threshold, ClawHub may apply the account action automatically. Lower-confidence and bounded temporal review signals are excluded from automatic enforcement.

Deleted, banned, or disabled accounts cannot use ClawHub API tokens. If CLI authentication fails after account action, sign in to the web UI to check account status. If a ban or disabled account blocks sign-in or normal CLI access, use the ClawHub appeal form for recovery review.

If a scanner-triggered email identifies a skill or plugin version as malicious, download the stored scan results for the blocked submitted version: clawhub scan download <slug> --version <version>. For plugins, append --kind plugin. Review the scan output, fix the listing, increment the version number, and upload the corrected version.

Publisher guidance

To minimize false positives and strengthen user trust:

  • keep names, summaries, tags, and changelogs accurate
  • declare required environment variables and permissions
  • avoid obfuscated install commands
  • link to source when possible
  • use dry runs before publishing plugins
  • respond clearly if users or moderators ask about release behavior
691 words · updated Jul 27, 2026