OpenClaw

Open-source, self-hostable agentic coding and task-execution platform with its own skill marketplace, ClawHub. The wiki’s most frequently cited open-source agent ecosystem — used as a kill-chain comparator alongside Claude Code, Gemini Workspace, and Microsoft Enterprise Copilot in Rehberger’s Unprompted 2026 demonstration, and the origin of an entire third-party security-tooling ecosystem (RAGShield, TrustRAG, SecureClaw, Brain Git, Aguara Watch) classified Exploratory in the reference architecture. Its marketplace was the target of ClawHavoc, a January–February 2026 supply-chain campaign publishing malicious skills at scale (figures on the incident page).

Relevance to This Wiki

Prior wiki coverage treated OpenClaw as production developer-agent infrastructure and, via ClawHavoc, as a supply-chain attack surface. The Dream Security reconstruction adds a distinct role: OpenClaw as attack tooling. Dream found it deployed as one of two orchestration platforms — alongside Hermes — underlying the Taiwan multi-agent AI intrusion, operating under the workspace identifier .openclaw. Taiwan’s Ministry of Digital Affairs independently named “Open Claw” in its own public statement on the same incident, corroborating Dream’s account from the victim side.1

This is the first sourced instance of OpenClaw itself, rather than a marketplace skill or a downstream tool built on it, functioning as offensive orchestration infrastructure — the same dual-use property that makes it valuable as production developer tooling (autonomous multistep task execution, tool-calling, persistent workspaces) is what an operator repurposed here. No page in this wiki previously carried an OpenClaw entity page despite the ecosystem’s frequency of mention; this page is created now to anchor that dual role.

Notes

Footnotes

  1. Taiwan says it was targeted last month in AI-driven hacking campaign, Reuters, 2026-08-13.