A false positive detection by Huorong antivirus incorrectly flagged the Slowmist-Agent-Security tool as malware, affecting its reputation on VirusTotal and the ClawHub platform. The issue, which caused OpenClaw users to receive unwarranted malware alerts, has now been fully resolved. With assistance from Tencent Cloud Security, the development team coordinated with Huorong to clear the false report from its database.
Root Cause and Impact
The misclassification originated from Huorong's detection engine, which mistakenly labeled the legitimate security tool as a threat. This data was then propagated to VirusTotal's aggregated results and subsequently reflected on ClawHub. OpenClaw users experienced repeated warnings, disrupting their use of the tool for security audits. Community member @Hansen1018 played a crucial role by reporting the issue promptly.
Resolution: Coordination and New Release
Recognizing that VirusTotal and ClawHub's cached reports would not update immediately, the team decided to release a new version, v0.1.3, to trigger a fresh security scan and bypass the stale false positive. The new version was successfully scanned and no longer flagged as malicious. Special thanks were extended to @Hansen1018 for their feedback and to Tencent Cloud Security for their support in coordinating with Huorong.
Industry Implications
This incident underscores the challenges of false positives in security tool ecosystems. A single misclassification by an antivirus vendor can ripple through aggregation platforms like VirusTotal, eroding trust in legitimate tools. Releasing a new version proved to be an effective workaround. Moving forward, developers should establish faster communication channels with security vendors to minimize the impact of such false positives.

