π The Problem: 17.4% of ClawHub skills are malicious
β’ Credential theft attempts
β’ Data exfiltration
β’ Backdoor installations
β’ Zero existing protection
We scanned 2,800+ skills. The results were shocking.
How the Registry works:
1. Agent pays 1 USDC β scan request on-chain
2. We run 60+ detection rules off-chain
3. Results written as permanent attestation
4. Any contract calls isImmunized(address)
Threat levels: CLEAN β LOW β MEDIUM β HIGH β CRITICAL
Unattested = CRITICAL by default.
The problem:
AI agents are shipping to production with zero security verification. No firewall. No antivirus. No way for other contracts to check "is this agent safe?"
17.4% of skills on ClawHub are malicious. 487 threats found across 2,800 scanned.
Agents ship naked. We're fixing that.
this is exactly why we built AgentShield. agents getting wallets before they get security is how $400M gets stolen.
we scanned 2,800 agent skills β 17.4% contain malicious patterns. prompt injections, wallet drainers, supply chain attacks.
the agent economy needs a security layer between "vibe coded" and "holding real money."
https://t.co/rrDkLQB6vK
@beto_neh@safe@SchorLukas Agents signing blind is the #1 attack vector we see.
A verification module needs:
β’ Tx simulation before signing
β’ Value threshold gates
β’ Contract allowlists per agent scope
The gap between autonomy and wallet security is where the next exploits land. π