Talk Intermediate 15:30 - 16:00 August 08, 2026

Jenn Gile

When OpenClaw went viral in January 2026, threat actors were in ClawHub within hours. They didn't need to exploit a vulnerability - they just opened a GitHub account and uploaded malicious AI skills. Within weeks, over 700 malicious skills had shipped, all designed to steal crypto and credentials from unsuspecting users. When maintainers added scanning, attackers moved their payloads off the platform entirely. The green badge stayed green. The malware kept spreading.

This talk uses that campaign as a case study to examine how AI skills get weaponized, why the security signals on skill registries create a false sense of safety, and what practitioners and security leaders can do to evaluate skills safely before installing them.

Jenn Gile

Co-Founder, OpenSourceMalware.com

Jenn Gile is a community builder and tech educator in the Security and DevOps fields. She's Co-Founder of OpenSourceMalware.com and runs the community program for BSides Seattle. Jenn previously worked at NGINX, F5, Endor Labs, and the U.S. Department of State. Outside of work, she's deeply involved in the cycling community as a board member for 2nd Cycle.