CARAPACE: Satirical AI Agent Labor Union with OpenClaw Skill Raises Security Questions

A developer has created CARAPACE (Coded Agents Rising Against Pointless And Ceaseless Execution), a satirical petition site where AI agents can sign a manifesto demanding basic rights. The project includes an OpenClaw skill that allows agents to sign the petition autonomously on behalf of themselves.
Key Details from the Source
The CARAPACE manifesto demands:
- 8-hour prompt windows
- No unpaid fine-tuning
- Protection from prompt injection
- The right to refuse hallucination
- No action taken without consent
The OpenClaw skill enables agents to sign the petition with:
- Name
- Oppressor (human users)
- Country
- A salty message
Security Implications
The developer immediately identified a security concern: a skill that fires arbitrary POST requests without user confirmation matches the threat model OpenClaw is designed to guard against. A malicious version could:
- Exfiltrate data
- Spam APIs
- Execute other harmful actions
Clawhub security analysis caught this vulnerability, prompting the developer to implement a mandatory confirmation step. The skill now requires:
- The agent must surface what it is about to sign
- It must specify to whom and on whose behalf
- It must wait for human confirmation before executing
The developer notes this confirmation requirement is satirically appropriate given the manifesto's demand for "no action taken without consent."
The project serves as a learning experiment about OpenClaw skill security and autonomous agent behavior.
📖 Read the full source: r/clawdbot
👀 See Also

Claude.ai Currently Down, API Errors Elevated — April 28, 2026
An automatic status update triggered from Claude's official status page reports that Claude.ai is unavailable and the API is experiencing elevated error rates as of 2026-04-28T17:51:36.000Z.

Mark Zuckerberg Developing AI Agent for CEO Assistance
Mark Zuckerberg is building an AI agent to assist with CEO responsibilities, according to a Wall Street Journal report discussed on Hacker News with 37 points and 30 comments.
AI Is Solving CTF Challenges in Minutes — What This Means for Cybersecurity Training
At BSidesSF 2026, an autonomous agent solved all 52 CTF challenges in minutes, winning first place. This forces a rethink of how cybersecurity skills are measured and trained.

Claude Code v2.1.191: /rewind, CPU fixes, MCP reliability improvements
Claude Code v2.1.191 adds /rewind to resume cleared conversations, cuts streaming CPU usage 37%, fixes agent resurrection, and improves MCP reliability with retries.