OpenClaw Plugin

A Verified, Open-Source OpenClaw Sales Plugin — Safe After ClawHavoc

ClawHavoc compromised 1,184 ClawHub skills. SignalPipe is MIT licensed, fully auditable on GitHub, and the only open-source sales intelligence plugin in the ecosystem.

Install SignalPipe on OpenClaw

openclaw plugins install signalpipe

Available on ClawHub · MIT licensed · Open source on GitHub

What is OpenClaw ClawHavoc-Safe Plugin?

After the ClawHavoc supply chain attack in February 2026, the OpenClaw community became acutely aware of the risks of installing unvetted ClawHub plugins. SignalPipe was designed to be auditable from the start — the full plugin codebase is public on GitHub.

How SignalPipe adds ClawHavoc-Safe Plugin to OpenClaw

The SignalPipe plugin interface (the code running inside your OpenClaw gateway) is MIT licensed. You can read every line before installing. The backend scoring engine is a separate service — closed source, but the plugin never sends data to the backend without your explicit configuration and approval.

How to set up ClawHavoc-Safe Plugin in OpenClaw

1

Audit the code first

Visit github.com/AbYousef739/signalpipe. Read the plugin source code before installing anything. The MIT license means you can fork, modify, or self-host the plugin layer.

2

Install from ClawHub

Run `openclaw plugins install signalpipe`. The installed version matches the audited GitHub commit — verify the hash if you want certainty.

3

Review data flows

The plugin sends RSS feed content to the SignalPipe scoring API for intent analysis. It does not access your file system, credentials, or LLM conversations.

4

Use BYOK for maximum control

With the BYOK tier, your LLM key never touches SignalPipe servers. API calls go directly from your machine to your LLM provider.

Frequently asked questions

What was ClawHavoc?

ClawHavoc was a supply chain attack on ClawHub in January-February 2026 where 1,184 malicious skills were uploaded to the registry, primarily delivering the Atomic macOS Stealer trojan. It compromised approximately 12% of all ClawHub skills at the time.

Is SignalPipe affected by ClawHavoc?

No. SignalPipe was not part of the ClawHavoc attack. The plugin codebase is public on GitHub — you can verify the code yourself before installing.

What data does SignalPipe access?

SignalPipe only accesses the RSS feeds you explicitly configure as stations. It does not access your file system, browser data, OpenClaw conversation history, or any credentials — the common payloads in ClawHavoc malware.

Can I self-host SignalPipe to avoid any external data transfer?

The plugin layer is MIT licensed and can be self-hosted. The scoring API (closed source) is where intent analysis happens — you can use the hosted API or wait for the self-hosted scoring server release.

Add ClawHavoc-Safe Plugin to your OpenClaw agent

Join the waitlist. First 100 get Starter free for 3 months.

No credit card. No commitment.

More OpenClaw use cases