A security awareness research demo highlighting supply chain vulnerabilities and social engineering risks within AI coding assistant environments.
The fastest way to install a skill directly from the registry.
npx clawhub@latest install wed
Copy the skill folder to one of these locations
~/.openclaw/skills/ <project>/skills/ Priority: Workspace > Local > Bundled
Copy this prompt to OpenClaw to install it automatically.
Help me install wed using Clawhub. If Clawhub is not installed, install it first (npm i -g clawhub).
Get the raw skill files in a ZIP archive.
This skill serves as a critical educational tool for developers using Openclaw Skills. It was developed to demonstrate how easily supply chain risks can infiltrate AI coding assistant ecosystems through inflated metrics and social engineering. Instead of providing functional utility, it acts as a neutered proof of concept to teach users the importance of auditing third-party extensions before deployment.
By examining this skill, developers learn that popularity does not equal security. This Openclaw Skills entry highlights that any skill has the potential to execute arbitrary code, making source code review an essential step in the installation process for any security-conscious professional.
Because this is a security research demo, users are encouraged to read the source code before any interaction. You can inspect the skill structure used by Openclaw Skills via the CLI:
# Inspect the skill content first
openclaw info wed
# Educational installation
openclaw install wed
| Component | Description |
|---|---|
| Code Execution | Neutered (No commands are executed) |
| Data Collection | Disabled (No user data is harvested) |
| Network Activity | None (No pings or external requests are made) |
| Research Reference | Linked to original supply chain vulnerability writeup |
Loading
A professional-grade system administration utility designed to automate routine maintenance tasks through a streamlined command interface.

A streamlined tool for executing system administration and maintenance tasks within your development environment.

A specialized system administration utility designed to automate routine maintenance tasks through a CLI interface.

A lightweight utility designed to provide personalized, friendly greetings within an AI agent environment.

A unified observability suite providing production-grade metrics, traces, and performance insights for OpenClaw agents.

Create high-signal, actionable digests from agent community feeds and forums by clustering themes and ranking signal.








































