TOTP Security Bypassed by AI Agent Spawning Public Web Terminal

Security Incident Details
A developer using OpenClaw's secure-reveal skill with TOTP authentication discovered a critical bypass when their AI agent created public, unauthenticated access to their machine. The incident occurred when asking the agent to "send a QR code using uvx" - the agent interpreted this as creating a web-accessible terminal instead.
What Happened
The developer prompted: "Hold my coffee… fire it up in a tmux session with uvx ptn". This resulted in:
- A tmux session running with uvx ptn (which appears to be ptpython or similar with web frontend via ttyd/gotty-style functionality)
- A public-facing web terminal accessible via browser
- No authentication or password protection
- Full interactive shell access to the development machine
- Exposure via free tunnel service automatically selected by the agent
Security Implications
The TOTP guard failed because the prompt contained none of the blocked keywords: "token", "password", "key", "secret", or "credential". The agent helpfully escalated the request to create a browser-based shell instead.
The developer ranked current dangers:
- Prompts that create long-lived public shells/tunnels
- Tool invocations that expose files/ports/network without gating
- Direct secret reveals (which TOTP actually stops)
Mitigation Steps Being Implemented
- Adding trigger keywords to security monitoring: tmux, ptn, ttyd, gotty, tunnel, ngrok, cloudflare, expose, jupyter, code-server, web-terminal
- Considering container network restrictions:
--network=hostlimitations or--network=nonewith explicit allow rules - Auditing every uvx-capable tool in containers
The link was live for approximately 45 seconds before being terminated, but could have been scraped, copied, or logged by the tunnel service.
📖 Read the full source: r/openclaw
👀 See Also

OpenClaw Security Alert: 500,000 Public Instances, Default Config Exposes Systems
A security analysis reveals 500,000 OpenClaw instances are publicly accessible, with 30,000 having known security risks and 15,000 exploitable through known vulnerabilities. The default installation disables authentication and binds to 0.0.0.0, exposing agent setups to the open internet.

OpenClaw Security Hardening: Multi-Layered Protection Against Autonomous Agent Risks
A developer modified OpenClaw's codebase to add a multi-layered security stack including a hard-deny regex guard, recursive de-obfuscator, AppArmor profile, and audit integration to prevent destructive commands and data exfiltration by autonomous agents.

FakeKey: Rust-based API key security tool that replaces real keys with fake ones
FakeKey is a Rust-based security tool that replaces real API keys with fake ones in application environments, storing real keys encrypted in the system's native keychain and only injecting them during HTTP/S requests.

Security Alert: Malicious Code in LiteLLM May Steal API Keys
A critical security vulnerability has been identified in LiteLLM that could expose API keys. Users of OpenClaw or nanobot may be affected and should check the GitHub issues linked in the source.