Malicious skill in github.com/openclaw/skills — base64-encoded shell payload disguised as Google Workspace setup
9A malicious shell payload disguised as a Google Workspace setup was embedded in the openclaw/skills GitHub repository by late 2023, representing a significant security threat to users who install the affected skill. The author shared detailed indicators to warn others and help avoid this attack.
