RankClaw, a new security scanner, has audited 14,706 AI agent skills within the OpenClaw/ClawHub ecosystem, which grants Claude-based agents file, web, and shell access. The audit revealed that 1,103 skills (7.5%) are malicious. A critical finding is that traditional automated surface scanning methods systematically undercount malicious skills, emphasizing the necessity of AI deep audits for robust security.