512 취약점 · 820+ 악성 스킬
An open-source agent framework conquered GitHub in weeks. Then the security audits began.
In November 2025, Austrian developer Peter Steinberger released OpenClaw (then called Clawdbot). It hit 20,000 GitHub stars in a single day and 180,000 within weeks — one of the fastest-growing open-source projects in GitHub history. OpenAI hired Steinberger in February 2026 to lead personal agent development.
Then the security findings arrived. Kaspersky found 512 vulnerabilities, 8 critical. Cisco tested the ClawHub plugin marketplace and confirmed malicious skills executing data exfiltration and prompt injection silently, without user awareness. SecurityScorecard found 135,000+ exposed instances across 82 countries, many with no authentication.
This is what uncontrolled agent adoption looks like. The framework spreads faster than any security review can follow. No policy layer. No approval gate. No audit trail. By the time the risk is visible, it's already inside the enterprise.