Gate News: On March 26, GoPlus Security issued a security alert stating that Silverfort security researchers discovered a serious vulnerability in OpenClaw’s skill repository ClawHub. Attackers can bypass protection mechanisms by calling the internal function downloads:increment, and with just one curl request, they can increase download counts to over 20,000 within minutes. This pushes malicious skills to the top of search rankings, tricking users or AI agents into automatically installing them. Once a malicious skill is run, it can steal sensitive data such as crypto wallets and API keys. The vulnerability was fixed within 24 hours. GoPlus warns that high download numbers do not equate to safety and recommends using AgentGuard for security scanning and protection.