ClawHub moderation
What a report is actually for, where a code vulnerability belongs instead, and why abusing the button can cost you your own account
A registry that anyone can publish to needs a way for readers to flag what they find, and ClawHub's is the report button. The recurring mistake is treating it as a general-purpose complaint box. It is narrower than that, and the narrowness is what keeps the queue useful.
What a report is for
- Malicious listings, and metadata that misleads about what a release does.
- Undeclared credential or permission requirements, and install instructions that look suspicious.
- Impersonation, bad-faith registrations and trademark misuse.
- Anything that breaches the acceptable-usage policy. Reporting runs from the button on a skill page, or through the package reporting command and API.
Good reports are specific and actionable. Abuse of reporting can itself lead to account action.
Where a code vulnerability goes instead
A vulnerability in a third-party skill or plugin's own source code is not a ClawHub report. It goes directly to the publisher, or to the source repository linked from the listing, because ClawHub does not maintain or patch third-party code and filing it in the registry queue simply delays the person who can fix it. The registry's own advisories are for bugs in ClawHub itself: the website, API, CLI, registry, auth, scanning, moderation, or the download and install trust boundaries.
Holds, hidden listings and standing
- A severe finding or a policy problem can place a publisher or a listing under a moderation hold.
- Held or blocked releases can be hidden from search and install surfaces until the problem is resolved, which is why an absence from search is itself information.
- Account standing is affected by how you use the system, and that includes how you report: the button is not free of consequence.
Ownership disputes are a separate path again. An org, brand, package-scope, owner-handle or namespace argument goes through the namespace claim process rather than the in-product report flow or the account appeal form, and the same public-issue rules apply there. See ClawHub namespace claims for that process and Reading a ClawHub security audit for the labels a listing carries.
Reading the queue from the outside
The public moderation record is deliberately partial. A structured verdict with reason codes and evidence is available, but owners and moderators see raw evidence and hidden listings while a public caller gets a redacted form, and only for a listing that is already flagged and still visible. That asymmetry is the point: a stranger cannot use the endpoint to discover a problem that has not been published yet. For the endpoint itself, see The ClawHub HTTP endpoints, and for where a registry bug belongs, Reporting a ClawHub vulnerability.
On Diali
Diali hosts OpenClaw, and the listings your assistant installs from are moderated by the registry rather than by us. Each customer runs their own assistant, the runtime configuration is generated from the dashboard and replaced at each release, and state lives on a persistent volume, with daily snapshots and one-click restore available through the Backups add-on (included on Max). See Hosted OpenClaw on Diali for what the hosting includes and Diali pricing for what it costs.
- Report the marketplace, not the code.
- A specific, actionable report is the only kind worth filing.
- An absence from search can mean a hold, not a missing package.
Stop reading about it, build one
Set up an agent, pick a channel, and have it working inside the app you already keep open.
