Reporting Security Issues and Vulnerability Disclosure for ClawHub

Learn how to report security vulnerabilities in ClawHub through GitHub Security Advisories. This page also explains when and how vulnerabilities are publicly disclosed.

Read this when

  • Reporting a ClawHub security issue
  • Understanding ClawHub vulnerability disclosure
  • Distinguishing ClawHub platform issues from third-party skill or plugin issues

Security

You can submit security issues for ClawHub through GitHub Security Advisories at openclaw/clawhub.

GitHub Security Advisories are the right channel for vulnerabilities within ClawHub itself. High quality advisory reports typically cover bugs in these areas:

  • the ClawHub website, API, or CLI
  • registry publishing, downloads, installs, or artifact integrity
  • authentication, authorization, or API tokens
  • scanning, moderation, or report handling

Do not use ClawHub advisories for vulnerabilities found in a third party skill or plugin's own source code. Instead, report those directly to the publisher or the source repository linked from the ClawHub listing.

Vulnerability disclosure

Since ClawHub runs as a hosted cloud application, service level vulnerabilities are not publicly disclosed by default. Public disclosure happens only when evidence shows real user impact or when users must take action.

Real user impact includes confirmed exploitation, exposure of user data or secrets, malicious content reaching users because of a platform failure, or any issue requiring users to rotate credentials, update local software, or take other protective steps.

Vulnerabilities in user installed software are publicly disclosed. This includes ClawHub CLI packages, binaries, libraries, or other release artifacts that users need to update locally.

For install time audit labels, risk levels, findings, and interpretation, refer to Security Audits.

For marketplace reports, moderation holds, hidden listings, bans, and account standing, see Moderation and Account Safety.

229 words · updated Jul 27, 2026