85.06% of OpenClaw skills show privileged operations
85.06% of readable skills show privileged-operation evidence; three scanners reach only 21.67%–61.06% sensitivity, so no single score suffices.
ImportanceLocalEvidenceE2 unreplicated
In AI agent OpenClaw's public skill registry, 85.06% of readable skills contain evidence of privileged operations, and governing such a fast-expanding registry cannot rely on a single scanner score.
Previously, security screening of skill registries typically relied on one scanner's pass-or-block verdict, but three security scanners disagreed on 23,702 of the 61,990 skills they jointly covered, and after human adjudication their sensitivity was only 21.67%–61.06%, so single-score screening misses many skills with privileged operations.
The authors self-tested OpenClaw's public skill registry, comparing three security scanners across 61,990 jointly covered skills and deriving that sensitivity range after human adjudication of 23,702 disagreements; the authors say the paper was accepted to APSEC 2026.
The data are the authors' own tests and have not yet been reproduced by others; the preprint was posted to arXiv on September 15 (arXiv:2609.17274, "After the Party").