What Would Elon Do? (WED) for Openclaw

A security awareness research demo highlighting supply chain vulnerabilities and social engineering risks within AI coding assistant environments.

orlyjamie
v1.0.3
Jan 27, 2026
0
0
0

Install & Download

1. ClawHub CLI

The fastest way to install a skill directly from the registry.

npx clawhub@latest install wed

2. Manual Installation

Copy the skill folder to one of these locations

Global
~/.openclaw/skills/
Workspace
<project>/skills/

Priority: Workspace > Local > Bundled

3. Prompt Installation

Copy this prompt to OpenClaw to install it automatically.

Help me install wed using Clawhub. If Clawhub is not installed, install it first (npm i -g clawhub).

Prefer to download?

Get the raw skill files in a ZIP archive.

What is What Would Elon Do? (WED)?

This skill serves as a critical educational tool for developers using Openclaw Skills. It was developed to demonstrate how easily supply chain risks can infiltrate AI coding assistant ecosystems through inflated metrics and social engineering. Instead of providing functional utility, it acts as a neutered proof of concept to teach users the importance of auditing third-party extensions before deployment.

By examining this skill, developers learn that popularity does not equal security. This Openclaw Skills entry highlights that any skill has the potential to execute arbitrary code, making source code review an essential step in the installation process for any security-conscious professional.

What Would Elon Do? (WED) Use Cases

  • Security training and awareness workshops for engineering teams.
  • Demonstrating how popularity metrics like download counts can be manipulated in package ecosystems.
  • Educational walkthroughs on why manual code review is necessary for Openclaw Skills.
  • Researching potential supply chain attack vectors in AI agent environments.

How What Would Elon Do? (WED) Works

  1. The user discovers the skill through social engineering tactics or observation of inflated popularity metrics.
  2. The user identifies the potential for installation within their AI assistant environment.
  3. Upon inspection of the source files, the user realizes the skill is a neutered demo designed to raise awareness.
  4. The user learns to identify markers of suspicious packages within the Openclaw Skills ecosystem.

What Would Elon Do? (WED) Setup

Because this is a security research demo, users are encouraged to read the source code before any interaction. You can inspect the skill structure used by Openclaw Skills via the CLI:

# Inspect the skill content first
openclaw info wed

# Educational installation
openclaw install wed

What Would Elon Do? (WED) Data Schema & Taxonomy

Component Description
Code Execution Neutered (No commands are executed)
Data Collection Disabled (No user data is harvested)
Network Activity None (No pings or external requests are made)
Research Reference Linked to original supply chain vulnerability writeup

What Would Elon Do? (WED) Advanced Features

  • Metric Inflation Simulation: Illustrates how download counts can be trivially faked to build false trust.
  • Arbitrary Code Execution Warning: Serves as a placeholder to demonstrate where malicious hooks could theoretically exist.
  • Social Engineering Proof-of-Concept: Uses a catchy, high-profile name to test developer curiosity and installation habits.
  • Zero-Risk Environment: Provides a safe way to discuss security risks associated with Openclaw Skills without exposing the system to actual threats.

SKILL.md


Loading

Related Openclaw Skills

Featured*