{"slug": "tencent-aig-joins-clawscan", "title": "Tencent AIG joins ClawScan", "summary": "ClawScan integrated Tencent's AI-Infra-Guard (AIG) skill scanner into its open-source security review tool for ClawHub, running AIG alongside NVIDIA's SkillSpector on every uploaded skill and plugin. On a fixed 556-case subset of Tencent and CUHK-Shenzhen's SkillTrustBench, ClawScan matched 86.9% of the benchmark's labels and correctly classified 98.6% of malicious cases. Tencent found AIG and SkillSpector surfaced different risks even when using the same AI model, and the two teams now share anonymized disagreement cases and confirmed false positives to improve AIG's detection rules.", "body_md": "## AIG is now part of ClawHub review\n\nWe’ve integrated Tencent’s AI-Infra-Guard (AIG) into [ClawScan](https://github.com/openclaw/clawscan), the open-source command-line tool that powers security review on ClawHub. Every skill and plugin uploaded to ClawHub now runs through AIG as part of its security review.\n\n## How ClawScan works\n\nOur [ClawHub Security Signals paper](https://openclaw.ai/publications/clawhub-security-signals.pdf) showed how differently scanners can read the same skill. Each brings its own view of risk, and preserving those differences gives us more evidence to work with.\n\nClawScan runs AIG and NVIDIA’s SkillSpector security scanner independently on each skill or plugin. An AI judge then reviews both scanners’ findings alongside the uploaded files and makes a final security assessment.\n\nContributors can test different scanners, AI models, and review instructions against the same benchmark to measure whether a change improves the results.\n\n## What Tencent AIG adds\n\nTencent describes [AIG’s skill scanner](https://github.com/Tencent/AI-Infra-Guard/tree/main/skill-scan) as “an LLM-driven multi-stage code audit and vulnerability review pipeline.” It can follow the relationship between a skill’s instructions and the scripts, dependencies, and data flows behind them.\n\nAIG reviews nine categories of risk, from instruction hijacking and memory poisoning to remote payload execution, unauthorized access, persistence, and insecure dependencies.\n\n## Benchmarking the combined system\n\nWe worked with Tencent to evaluate ClawScan on a fixed 556-case subset of [SkillTrustBench](https://matrix.tencent.com/skilltrustbench/), the public benchmark developed by Tencent and the Chinese University of Hong Kong, Shenzhen.\n\nSkillTrustBench includes benign, suspicious, and malicious skills across nine risk categories. It tests whether scanners catch risky behavior, avoid flagging legitimate skills, and distinguish security flaws from malicious intent.\n\nThe evaluation helped us validate the scanner settings and the combined review process. Tencent found that AIG and SkillSpector surfaced different risks even when using the same AI model.\n\n**Across those 556 cases, ClawScan matched 86.9% of the benchmark’s labels and correctly classified 98.6% of malicious cases.**\n\n## Improving both projects together\n\nWe now share anonymized cases where the scanners disagree, along with confirmed false positives, with Tencent. These examples feed into regression tests and improvements to AIG’s detection rules and review process. We evaluate those changes through ClawScan, creating a feedback loop that improves both projects.\n\nKeeping this work open lets contributors build on the integration and bring their own evidence to the next round of improvements.\n\n## Acknowledgments\n\nWe’re grateful to the Tencent team for contributing their scanner, benchmark, and time to this work, from reviewing individual results to resolving production issues.", "url": "https://wpnews.pro/news/tencent-aig-joins-clawscan", "canonical_source": "https://openclaw.ai/blog/tencent-aig-joins-clawscan/", "published_at": "2026-10-02 00:00:00+00:00", "updated_at": "2026-10-02 18:38:42.715680+00:00", "lang": "en", "topics": ["ai-safety", "ai-tools", "developer-tools", "ai-agents"], "entities": ["Tencent", "AI-Infra-Guard", "ClawScan", "ClawHub", "NVIDIA", "SkillSpector", "SkillTrustBench", "Chinese University of Hong Kong, Shenzhen"], "also_reported_by": [], "alternates": {"html": "https://wpnews.pro/news/tencent-aig-joins-clawscan", "markdown": "https://wpnews.pro/news/tencent-aig-joins-clawscan.md", "text": "https://wpnews.pro/news/tencent-aig-joins-clawscan.txt", "jsonld": "https://wpnews.pro/news/tencent-aig-joins-clawscan.jsonld"}}