Introduction

By mid-2026, the OpenClaw Foundation plans to launch an official Extension Marketplace for community-built skills. This will centralize the "agentic economy," making it easier for users to find trusted automation for specific industries like banking, logistics, and retail. The marketplace is a response to ClawHavoc — replacing the unvetted ClawHub registry with a curated, audited platform.

Current State: ClawHub

ClawHub is the current community skill registry. Anyone can upload a skill; there's no formal review. The ClawHavoc attack demonstrated the risks: 12-20% of skills were malicious. The Foundation now works with VirusTotal for scanning, but a more comprehensive solution is needed.

Marketplace Vision

The official Extension Marketplace will provide:

  • Curated catalog: Skills reviewed before listing
  • Categories: Banking, logistics, retail, productivity, dev tools
  • Ratings and reviews: User feedback, download counts
  • One-click install: Integrated into OpenClaw CLI and config
  • Versioning: Semantic versioning, changelogs, update notifications

Auditing & Review

Skills will undergo automated and manual review:

  • Automated: VirusTotal scan, static analysis for suspicious patterns (eval, network calls, file access)
  • Manual: Foundation or community maintainers review code for high-risk skills
  • Ongoing: Flagged skills removed; repeat offenders banned

Verified publishers (companies, well-known contributors) get badge; higher trust.

Industry-Specific Skills

The marketplace will prioritize industry verticals:

  • Banking: Transaction monitoring, compliance checks, report generation
  • Logistics: Shipment tracking, inventory alerts, carrier API integration
  • Retail: Price monitoring, order management, customer support automation

These skills will have stricter auditing due to sensitivity of data and regulatory requirements.

Timeline

Target: Q2 2026. Foundation is currently defining the threat model, audit criteria, and publisher onboarding process. Beta may launch with a limited skill set before full public availability. The ClawHavoc and 340 malicious skills incidents accelerated the timeline. The community can't wait for a vetted ecosystem — the risk is too high.

Migration from ClawHub

When the Extension Marketplace launches, existing ClawHub skills will need to migrate. Publishers will submit skills for review. Skills that pass automated and manual audit get listed. Skills that fail get feedback. The Foundation is designing a migration path so popular skills can transition smoothly. Expect a grace period where both ClawHub and the Marketplace coexist. See ClawHub for the current state.

Publisher Requirements

To publish on the Extension Marketplace: verified identity (GitHub, company domain, or similar), agreement to security and code quality standards, and acceptance of ongoing monitoring. Verified publishers get a badge; their skills appear higher in search. Repeat offenders get banned. The goal is to create a trust layer that ClawHub never had.

Wrapping Up

The Extension Marketplace will transform OpenClaw from "install skills at your own risk" to "trusted, curated ecosystem." See ClawHub and roadmap for updates.