OpenClaw integrates VirusTotal Code Insight scanning for ClawHub skills following reports of malicious plugins, prompt injection & exposed instances.
Attackers can abuse VS Code configuration files for RCE when a GitHub Codespaces user opens a repository or pull request.