Documents the rapid growth of the OpenClaw public AI-agent skill registry, which nearly doubled in 91 days with most listings created in two months.
OpenClaw’s public skill registry, ClawHub, nearly doubled its observable stock from 33,399 to 65,175 listings in 91 days during early 2026, with 63.25% of the June visible listings created in just March and April.
Key findings from the study include: Concentrated Attention: The top 10% of skills accounted for 46.93% of all downloads, while the majority of listings received minimal engagement. Sparse Governance: 77.86% of listings had zero stars and zero comments, indicating a lack of human scrutiny despite 85.06% of readable skills carrying privilege evidence. * Scanner Inconsistency: Automated security scanners disagreed on 23,702 of the 61,990 skills they covered, with weighted sensitivity ranging from 21.67% to 61.06%, highlighting the limitations of relying on single scanner scores for governance.
This paper examines the OpenClaw public AI-agent skill registry as an emerging distribution layer for executable agent capabilities. Its central empirical observation is that the registry grew very rapidly, nearly doubling over a 91-day period, with most listings created within roughly the final two months of that window. That concentration of new entries suggests a burst of contributor activity, experimentation, and low-friction onboarding rather than slow, curated maturation, making OpenClaw a useful case study for how agent-skill ecosystems can scale quickly in practice.
Beyond growth measurement, the work frames OpenClaw in terms of governance and security scanning for agent skills. Because skills may be discovered, installed, or invoked by autonomous agents, the registry functions like a supply chain for agent behavior: provenance, moderation, permission boundaries, dependency handling, and malicious-skill detection all affect downstream risk. The paper’s contribution is to provide an early empirical account of how fast such an ecosystem can expand and what governance and security questions that expansion makes urgent.
This matters because agent skill registries are becoming a practical attack surface and trust boundary for LLM-agent systems. If skills are inadequately governed or scanned, they can introduce prompt-injection, credential leakage, excessive permissions, or malicious code into otherwise trusted agent workflows. The paper therefore offers a timely baseline for platform designers, security researchers, and agent developers who need to balance open innovation with supply-chain assurance in agent ecosystems.