A new study of the AI agent OpenClaw's skill ecosystem shows the boom left mostly unchecked code behind.
The paper, "After the Party: Governing What a Viral Agent-Skill Ecosystem Left Behind" (arXiv:2609.17274), traces the first half of 2026, when OpenClaw went viral and its public ClawHub skill registry exploded. The observable stock of skills nearly doubled in 91 days, and most listings visible in June had been created in just the prior two months. Researchers mined the OpenClaw Git history, its GitHub issues and pull requests, and three ClawHub registry snapshots to see what that growth left behind. By the end of the study window, listing creation and core-repository activity were already falling from their spring peaks.
The numbers are not reassuring. The top 10% of skills account for 46.93% of all downloads, 77.86% of listings have zero stars and zero comments, and 85.06% of readable skills carry evidence of requesting elevated privileges, the kind of shell, network, credential, or file access that matters most if something goes wrong. Once creation cohort and age are controlled for, none of the obvious signals, like size or download counts, reliably predict which skills stick around.
Automated policing looks even shakier: three security scanners disagreed on 23,702 of the 61,990 skills they all covered, and after human adjudication their sensitivity against a reference standard ranged from just 21.67% to 61.06%. That is the real lesson here: a plugin marketplace can double in three months, but the tooling to vet what is actually in it does not scale nearly as fast.