The ClawHavoc campaign exposed a fundamental architectural flaw in OpenClaw: all skills share a single plaintext credential file with no delegation model. Over 800 malicious skills on ClawHub exploited this to exfiltrate tokens. The real fix isn't better secret hygiene — it's applying OAuth-style delegation to AI agents. Auth0
Table of contents
What We Mean by DelegationWhat ClawHavoc Looked Like from Where We SitA Tool You Can Use Right NowGoing Deeper with Fine-Grained AuthorizationThe Pattern RepeatsSort: