Skip to content
All tool news

Tool desk · Updated daily

Tool news·OpenClaw·

OpenClaw Adds Tencent AIG to Every ClawHub Security Review.

OpenClaw adds Tencent AIG to ClawScan, reviewing every ClawHub upload with two scanners, an AI judge and benchmark testing.

CW

Create With tool desk

3 sources checked · 2 min read · 3 sections

ShareLinkedIn
OpenClaw Adds Tencent AIG to Every ClawHub Security Review

Tencent AIG now reviews every skill and plugin uploaded to OpenClaw’s ClawHub. It runs inside ClawScan alongside NVIDIA’s SkillSpector, with an AI judge making the final security assessment.

The change adds a second independent view of each upload. ClawScan is the open-source command-line tool behind ClawHub’s security reviews. According to the OpenClaw blog post, both scanners inspect the files separately before the judge considers their findings and the uploaded code.

What Tencent AIG Checks

Tencent describes AIG, short for AI-Infra-Guard, as an LLM-driven, multi-stage pipeline for code audits and vulnerability reviews. It examines the relationship between a skill’s instructions and its scripts, dependencies and data flows.

The scanner covers nine risk categories. These include instruction hijacking, memory poisoning, remote payload execution, malicious code, unauthorised access, persistence and insecure dependencies.

ClawHub’s audit view lists Tencent AIG checks for instruction hijacking, memory poisoning, remote payload execution, malicious code and unauthorised access.
ClawHub’s audit view lists Tencent AIG checks for instruction hijacking, memory poisoning, remote payload execution, malicious code and unauthorised access.

AIG and SkillSpector can reach different conclusions about the same upload. ClawScan preserves both sets of findings rather than combining them into one scanner result. Its AI judge then reviews that evidence with the original files.

ClawScan’s Benchmark Results

OpenClaw and Tencent tested the combined system against 556 cases from SkillTrustBench. The public benchmark was developed by Tencent and the Chinese University of Hong Kong, Shenzhen. It contains benign, suspicious and malicious skills across nine risk categories.

Benchmark cases
556
fixed subset of SkillTrustBench
Labels matched
86.9%
across the benchmark subset
Malicious cases classified correctly
98.6%
in the same evaluation

Contributors can use the benchmark to compare different scanners, AI models and review instructions. This provides a fixed set of cases for checking whether a proposed change improves classification.

Tencent and OpenClaw will also share anonymised cases where their scanners disagree. Those cases feed an ongoing review loop intended to improve both scanning systems.

Frequently asked questions

What is Tencent AIG in OpenClaw?

Tencent AIG is an LLM-driven scanner for code audits and vulnerability reviews. It is now part of ClawScan, which checks every skill and plugin uploaded to ClawHub.

How does Tencent AIG work with SkillSpector?

AIG and NVIDIA’s SkillSpector scan each upload independently. An AI judge reviews both sets of findings alongside the uploaded files and makes the final security assessment.

When is Tencent AIG available for ClawHub uploads?

Tencent AIG is now included in ClawHub’s security review process. Every uploaded skill and plugin runs through it as part of ClawScan.

Sources

3 checked

How we cover tool news: Create With's tool desk drafts these reports with AI from the sources listed above and checks them against those sources before publishing.

Worth passing on?

ShareLinkedIn

Go deeper on OpenClaw

Related reading, watching and going.

Everything on OpenClaw →

The briefing

1 Sept 2026

GrokBot Tested: Two Conflicting Takes from Create With

Two Create With writers test GrokBot - an app giving each AI bot a cloud PC and letting bots message each other. We share opposing takes and pricing notes.

Read →

The briefing

28 Jul 2026

AI Loops Explained: Practical Guide Without the Hype

Understand AI 'loops'—how goal-driven agents replace manual prompts, when they help, and their real costs. A clear, no-hype primer for builders and teams.

Read →

The briefing

7 Jul 2026

Create With 2026: One Hot Day in Brighton — AI Agents

Recap of Create With 2026 in Brighton: 500+ creators, live AI-agent demos, Claude Cowork workshop, 50+ apps shipped, a 45-project hackathon and community magic.

Read →
36 min

Podcast

55. We're Back! Conference Recap, Running Events with AI & Self-Healing Apps

James and Kieran return to the Create With Podcast after their summer break to recap the 2026 Create With Conference in Brighton. They discuss how 550 attendees experienced workshops, a charity hackathon where functional apps were built in 30 minutes, and an innovative conference operating system built entirely with AI. The episode covers the latest developments in AI development tools including Anthropic's Fable model, scheduled tasks in Codex, and self-healing applications using PostHog.

Watch now ↗
56 min

Tutorial

OpenClaw + custom dashboard + subagents = mindblowing!

Benoit Devilliers demonstrates Visionary, a custom dashboard he built on top of OpenClaw that uses an orchestrator/sub-agent architecture. The system manages client projects, spawns specialized coding agents, and sends push notifications. In a live demo, he shapes a ticket, spawns an agent, and merges a PR in real-time. Benoit started AI coding in July 2024 and built this entire system himself, showcasing how accessible these tools have become.

Watch now ↗

Podcast

53. Why Your Vibe Code Needs Tests, Ditching SaaS & AI Agents That Work While You Sleep

James and Kieran discuss the practical realities of building AI-powered software, emphasizing the importance of testing in vibe-coded applications, exploring alternatives to traditional SaaS tools, and implementing autonomous AI agents for business operations. The episode covers technical topics like Convex databases, app store bottlenecks from AI-generated submissions, and using OpenClaw as a marketing automation agent.

Watch now ↗

Latest tool news

What else changed this week.

All tool news
MakeDigest

What Make Shipped in Early October

Make shipped a small but useful reliability update for people building automations in the editor. This one is about protecting work in progress, following broader recent changes…

The Create With Briefing

Don't watch forty changelogs. Read one email.

Every Tuesday: the tool changes worth knowing, real business use cases, and what's on near you. Free, unsubscribe any time.