This preprint presents a comprehensive, data-driven assessment of the OpenClaw autonomous AI agent ecosystem's security posture, synthesizing findings from 12+ security research organizations. We analyze four layers of the attack surface: (1) supply chain poisoning via the ClawHub skill marketplace (1,184+ confirmed malicious skills), (2) deployment misconfiguration and credential exposure (42,000+ internet-exposed instances, 93% with authentication bypass), (3) end-to-end exploitation paths including CVE-2026-25253 (CVSS 8.8), and (4) governance gaps in platform and institutional responses. We propose a four-dimensional threat model T=(D,U,C,M) extending Willison's "lethal trifecta" with persistent memory. Data sources include reports from Cisco, Trend Micro, Snyk, Bitdefender, Kaspersky, Microsoft, and Palo Alto Networks.
Gangyi Zhang (Wed,) studied this question.