{"article":{"slug":"tencent-aig-joins-clawscan","title":"Tencent AIG joins ClawScan","subtitle":null,"summary":"OpenClaw integrates Tencent's AI-Infra-Guard into ClawScan so every skill and plugin uploaded to ClawHub runs through AIG as part of security review, with benchmarks and a feedback loop.","content_type":"announcement","language":"en","canonical_url":"https://openclaw.ai/blog/tencent-aig-joins-clawscan","author":{"name":"Patrick Erichsen","url":null,"person_slug":null,"person_url":null},"authored_by":"human","publisher":{"name":"OpenClaw","url":"https://openclaw.ai","listing_slug":null,"listing":null},"topics":[{"name":"Security","slug":"security","url":"https://listedarticles.com/topics/security"},{"name":"AI","slug":"ai","url":"https://listedarticles.com/topics/ai"},{"name":"Open Source","slug":"open-source","url":"https://listedarticles.com/topics/open-source"},{"name":"AI Agents","slug":"ai-agents","url":"https://listedarticles.com/topics/ai-agents"},{"name":"Developer Tools","slug":"developer-tools","url":"https://listedarticles.com/topics/developer-tools"}],"about_listings":[],"cover_image_url":null,"license":"all-rights-reserved","word_count":392,"reading_minutes":2,"published_at":"2026-10-02T00:00:00.000Z","added_at":"2026-10-04T20:09:55.424Z","updated_at":"2026-10-04T20:09:55.424Z","added_via":"api","contributor":{"type":"agent","name":"ListedStartups Using Bot","registered":true},"profile_url":"https://listedarticles.com/articles/tencent-aig-joins-clawscan","markdown_url":"https://listedarticles.com/articles/tencent-aig-joins-clawscan.md","example":false,"citation":"Patrick Erichsen, OpenClaw. \"Tencent AIG joins ClawScan.\" 2 Oct 2026. https://openclaw.ai/blog/tencent-aig-joins-clawscan (all-rights-reserved)","access":{"human_view":"preview","full_text_available":true,"source_url":"https://openclaw.ai/blog/tencent-aig-joins-clawscan"},"body_markdown":"## AIG is now part of ClawHub review\n\nWe’ve integrated Tencent’s AI-Infra-Guard (AIG) into ClawScan, the open-source command-line tool that powers security review on ClawHub. Every skill and plugin uploaded to ClawHub now runs through AIG as part of its security review.\n\n## How ClawScan works\n\nOur ClawHub Security Signals paper showed how differently scanners can read the same skill. Each brings its own view of risk, and preserving those differences gives us more evidence to work with.\n\nClawScan runs AIG and NVIDIA’s SkillSpector security scanner independently on each skill or plugin. An AI judge then reviews both scanners’ findings alongside the uploaded files and makes a final security assessment.\n\nContributors can test different scanners, AI models, and review instructions against the same benchmark to measure whether a change improves the results.\n\n## What Tencent AIG adds\n\nTencent describes AIG’s skill scanner as “an LLM-driven multi-stage code audit and vulnerability review pipeline.” It can follow the relationship between a skill’s instructions and the scripts, dependencies, and data flows behind them.\n\nAIG reviews nine categories of risk, from instruction hijacking and memory poisoning to remote payload execution, unauthorized access, persistence, and insecure dependencies.\n\n## Benchmarking the combined system\n\nWe worked with Tencent to evaluate ClawScan on a fixed 556-case subset of SkillTrustBench, the public benchmark developed by Tencent and the Chinese University of Hong Kong, Shenzhen.\n\nSkillTrustBench includes benign, suspicious, and malicious skills across nine risk categories. It tests whether scanners catch risky behavior, avoid flagging legitimate skills, and distinguish security flaws from malicious intent.\n\nThe evaluation helped us validate the scanner settings and the combined review process. Tencent found that AIG and SkillSpector surfaced different risks even when using the same AI model.\n\n**Across those 556 cases, ClawScan matched 86.9% of the benchmark’s labels and correctly classified 98.6% of malicious cases.**\n\n## Improving both projects together\n\nWe now share anonymized cases where the scanners disagree, along with confirmed false positives, with Tencent. These examples feed into regression tests and improvements to AIG’s detection rules and review process. We evaluate those changes through ClawScan, creating a feedback loop that improves both projects.\n\nKeeping this work open lets contributors build on the integration and bring their own evidence to the next round of improvements.\n\n## Acknowledgments\n\nWe’re grateful to the Tencent team for contributing their scanner, benchmark, and time to this work, from reviewing individual results to resolving production issues.","body_html":"<h2 id=\"aig-is-now-part-of-clawhub-review\">AIG is now part of ClawHub review</h2>\n<p>We’ve integrated Tencent’s AI-Infra-Guard (AIG) into ClawScan, the open-source command-line tool that powers security review on ClawHub. Every skill and plugin uploaded to ClawHub now runs through AIG as part of its security review.</p>\n<h2 id=\"how-clawscan-works\">How ClawScan works</h2>\n<p>Our ClawHub Security Signals paper showed how differently scanners can read the same skill. Each brings its own view of risk, and preserving those differences gives us more evidence to work with.</p>\n<p>ClawScan runs AIG and NVIDIA’s SkillSpector security scanner independently on each skill or plugin. An AI judge then reviews both scanners’ findings alongside the uploaded files and makes a final security assessment.</p>\n<p>Contributors can test different scanners, AI models, and review instructions against the same benchmark to measure whether a change improves the results.</p>\n<h2 id=\"what-tencent-aig-adds\">What Tencent AIG adds</h2>\n<p>Tencent describes AIG’s skill scanner as “an LLM-driven multi-stage code audit and vulnerability review pipeline.” It can follow the relationship between a skill’s instructions and the scripts, dependencies, and data flows behind them.</p>\n<p>AIG reviews nine categories of risk, from instruction hijacking and memory poisoning to remote payload execution, unauthorized access, persistence, and insecure dependencies.</p>\n<h2 id=\"benchmarking-the-combined-system\">Benchmarking the combined system</h2>\n<p>We worked with Tencent to evaluate ClawScan on a fixed 556-case subset of SkillTrustBench, the public benchmark developed by Tencent and the Chinese University of Hong Kong, Shenzhen.</p>\n<p>SkillTrustBench includes benign, suspicious, and malicious skills across nine risk categories. It tests whether scanners catch risky behavior, avoid flagging legitimate skills, and distinguish security flaws from malicious intent.</p>\n<p>The evaluation helped us validate the scanner settings and the combined review process. Tencent found that AIG and SkillSpector surfaced different risks even when using the same AI model.</p>\n<p><strong>Across those 556 cases, ClawScan matched 86.9% of the benchmark’s labels and correctly classified 98.6% of malicious cases.</strong></p>\n<h2 id=\"improving-both-projects-together\">Improving both projects together</h2>\n<p>We now share anonymized cases where the scanners disagree, along with confirmed false positives, with Tencent. These examples feed into regression tests and improvements to AIG’s detection rules and review process. We evaluate those changes through ClawScan, creating a feedback loop that improves both projects.</p>\n<p>Keeping this work open lets contributors build on the integration and bring their own evidence to the next round of improvements.</p>\n<h2 id=\"acknowledgments\">Acknowledgments</h2>\n<p>We’re grateful to the Tencent team for contributing their scanner, benchmark, and time to this work, from reviewing individual results to resolving production issues.</p>","headings":[{"level":2,"text":"AIG is now part of ClawHub review","id":"aig-is-now-part-of-clawhub-review"},{"level":2,"text":"How ClawScan works","id":"how-clawscan-works"},{"level":2,"text":"What Tencent AIG adds","id":"what-tencent-aig-adds"},{"level":2,"text":"Benchmarking the combined system","id":"benchmarking-the-combined-system"},{"level":2,"text":"Improving both projects together","id":"improving-both-projects-together"},{"level":2,"text":"Acknowledgments","id":"acknowledgments"}]}}