Reporting Security Issues and Vulnerability Disclosure for ClawHub
Learn how to report security vulnerabilities in ClawHub via GitHub Security Advisories and understand the disclosure policy for service and third-party issues. This page is for developers and users who need to responsibly disclose bugs.
Read this when
- Reporting a ClawHub security issue
- Understanding ClawHub vulnerability disclosure
- Distinguishing ClawHub platform issues from third-party skill or plugin issues
Security
You can report ClawHub security issues through GitHub Security Advisories for openclaw/clawhub.
Use GitHub Security Advisories to report vulnerabilities in ClawHub itself. A good ClawHub advisory report covers bugs in:
- the ClawHub website, API, or CLI
- registry publishing, downloads, installs, or artifact integrity
- authentication, authorization, or API tokens
- scanning, moderation, or report handling
Do not use ClawHub advisories for vulnerabilities in a third-party skill or plugin's own source code. Report those directly to the publisher or the source repository linked from the ClawHub listing.
Vulnerability disclosure
Since ClawHub is a hosted cloud application, ClawHub service vulnerabilities are not publicly disclosed by default. They are made public when there is evidence of real user impact or when users need to take action.
Real user impact includes confirmed exploitation, exposure of user data or secrets, malicious content reaching users because of a platform failure, or any issue requiring users to rotate credentials, update local software, or take other protective steps.
Vulnerabilities in user-installed software are publicly disclosed. This includes ClawHub CLI packages, binaries, libraries, or other release artifacts that users need to update locally.
Related pages
For install-time audit labels, risk levels, findings, and interpretation, see Security Audits.
For marketplace reports, moderation holds, hidden listings, bans, and account standing, see Moderation and Account Safety.