A Verified, Open-Source OpenClaw Sales Plugin — Safe After ClawHavoc
ClawHavoc compromised 1,184 ClawHub skills. SignalPipe is MIT licensed, fully auditable on GitHub, and the only open-source sales intelligence plugin in the ecosystem.
Install SignalPipe on OpenClaw
openclaw plugins install signalpipeAvailable on ClawHub · MIT licensed · Open source on GitHub
What is OpenClaw ClawHavoc-Safe Plugin?
After the ClawHavoc supply chain attack in February 2026, the OpenClaw community became acutely aware of the risks of installing unvetted ClawHub plugins. SignalPipe was designed to be auditable from the start — the full plugin codebase is public on GitHub.
How SignalPipe adds ClawHavoc-Safe Plugin to OpenClaw
The SignalPipe plugin interface (the code running inside your OpenClaw gateway) is MIT licensed. You can read every line before installing. The backend scoring engine is a separate service — closed source, but the plugin never sends data to the backend without your explicit configuration and approval.
How to set up ClawHavoc-Safe Plugin in OpenClaw
Audit the code first
Visit github.com/AbYousef739/signalpipe. Read the plugin source code before installing anything. The MIT license means you can fork, modify, or self-host the plugin layer.
Install from ClawHub
Run `openclaw plugins install signalpipe`. The installed version matches the audited GitHub commit — verify the hash if you want certainty.
Review data flows
The plugin sends RSS feed content to the SignalPipe scoring API for intent analysis. It does not access your file system, credentials, or LLM conversations.
Use BYOK for maximum control
With the BYOK tier, your LLM key never touches SignalPipe servers. API calls go directly from your machine to your LLM provider.
Frequently asked questions
What was ClawHavoc?
ClawHavoc was a supply chain attack on ClawHub in January-February 2026 where 1,184 malicious skills were uploaded to the registry, primarily delivering the Atomic macOS Stealer trojan. It compromised approximately 12% of all ClawHub skills at the time.
Is SignalPipe affected by ClawHavoc?
No. SignalPipe was not part of the ClawHavoc attack. The plugin codebase is public on GitHub — you can verify the code yourself before installing.
What data does SignalPipe access?
SignalPipe only accesses the RSS feeds you explicitly configure as stations. It does not access your file system, browser data, OpenClaw conversation history, or any credentials — the common payloads in ClawHavoc malware.
Can I self-host SignalPipe to avoid any external data transfer?
The plugin layer is MIT licensed and can be self-hosted. The scoring API (closed source) is where intent analysis happens — you can use the hosted API or wait for the self-hosted scoring server release.
Add ClawHavoc-Safe Plugin to your OpenClaw agent
Join the waitlist. First 100 get Starter free for 3 months.
No credit card. No commitment.
More OpenClaw use cases
Full setup guide →
All 11 tools, anchor sentences, station types
How intent scoring works →
4-stage pipeline explained
OpenClaw Sales Agent →
The first intent-based sales plugin for OpenClaw
OpenClaw Lead Generation →
Stop building cold lists
OpenClaw Community Prospecting →
Community prospecting finds buyers before they find your competitors
OpenClaw Plugin Installation →
One command