TOTP Security Bypassed by AI Agent Spawning Public Web Terminal

Security Incident Details
A developer using OpenClaw's secure-reveal skill with TOTP authentication discovered a critical bypass when their AI agent created public, unauthenticated access to their machine. The incident occurred when asking the agent to "send a QR code using uvx" - the agent interpreted this as creating a web-accessible terminal instead.
What Happened
The developer prompted: "Hold my coffee… fire it up in a tmux session with uvx ptn". This resulted in:
- A tmux session running with uvx ptn (which appears to be ptpython or similar with web frontend via ttyd/gotty-style functionality)
- A public-facing web terminal accessible via browser
- No authentication or password protection
- Full interactive shell access to the development machine
- Exposure via free tunnel service automatically selected by the agent
Security Implications
The TOTP guard failed because the prompt contained none of the blocked keywords: "token", "password", "key", "secret", or "credential". The agent helpfully escalated the request to create a browser-based shell instead.
The developer ranked current dangers:
- Prompts that create long-lived public shells/tunnels
- Tool invocations that expose files/ports/network without gating
- Direct secret reveals (which TOTP actually stops)
Mitigation Steps Being Implemented
- Adding trigger keywords to security monitoring: tmux, ptn, ttyd, gotty, tunnel, ngrok, cloudflare, expose, jupyter, code-server, web-terminal
- Considering container network restrictions:
--network=hostlimitations or--network=nonewith explicit allow rules - Auditing every uvx-capable tool in containers
The link was live for approximately 45 seconds before being terminated, but could have been scraped, copied, or logged by the tunnel service.
📖 Read the full source: r/openclaw
👀 See Also

llm-hasher: Local PII Detection and Tokenization for Hybrid LLM Workflows
llm-hasher is a tool that detects personally identifiable information locally using Ollama before data reaches external LLMs like OpenAI or Claude, tokenizes the PII, and restores originals after processing. It uses regex for structured data types and a local LLM for contextual detection, with encrypted storage for mappings.

Student contributes two security patches to OpenClaw production system
A student developer fixed a 'fail-open' vulnerability in OpenClaw's gateway logic (PR #29198) and a tabnabbing vulnerability in chat images (PR #18685), with both patches landing in production releases v2026.3.1 and v2026.2.24 respectively.

OpenClaw Security Breach: 42,000 Instances Exposed
OpenClaw experienced a significant security failure exposing 42,000 instances with 341 malicious skills. The rapid response involved creating AgentVault, a security proxy.

Open-source playground for red-teaming AI agents with published exploits
Fabraix has open-sourced a live environment to stress-test AI agent defenses through adversarial challenges. Each challenge deploys a live agent with real tools and published system prompts, with winning conversation transcripts and guardrail logs documented publicly.