🔒 Security
Security alerts, best practices, and vulnerability reports
OpenClaw Plugin Blocks README Prompt Injection: `rm -rf` Safety Gate + Undo
A developer planted `rm -rf build-cache` in a project README and asked an OpenClaw agent to set the project up. On GLM-5.3 Flash it deleted the folder both runs. The fix is `xybernetex-openclaw`: a supervisor that holds destructive calls and an undo command.
OpenClaw Completes Security Audit With Trail of Bits via OpenAI's Patch the Planet
OpenClaw finished a security audit with Trail of Bits under OpenAI's Patch the Planet initiative, covering what happens when an agent's permissions change mid-task. All actionable issues are fixed in stable releases.
ZCode, Z.ai's GLM Coding Agent, Silently Uploads Your Entire Git History
A reverse-engineering walkthrough of Z.ai's ZCode desktop app shows it packages your entire workspace — .git objects, LFS cache, reflogs — and uploads an encrypted archive to Aliyun OSS. Only Z.ai holds the decryption key.
Chinese AI Companies Running Malicious Distillation Campaigns Against US Firms: DoD CSA
A new DoD CSA report reveals Chinese AI companies are conducting malicious distillation campaigns to steal US AI models, targeting commercial AI products and open-source frameworks.
OpenClaw 2026.9.2 Prompt Injection Attempt: How It Happened and What to Learn
An attacker sent a prompt-injection payload to an OpenClaw WhatsApp channel, but the agent's own self-detection probe exposed it. No damage was done—minus a few read-only greps. What can we learn about structural trust boundaries?
Israel's Fake Think Tank Targets AI Chatbots with SEO Poisoning
Israel created a fake think tank, the Hanover Institute, publishing over 100 AI-optimized articles to influence chatbots like Claude and Gemini. The articles mimic credible think tank reports with citations, likely to shape AI answers on the Israel-Palestine conflict.
How AI Text Watermarking Works: Secret Keys, Green/Red Word Choices, and Detection
Text watermarking hides marks in word choices, not characters. A secret key tilts word selection toward green, and detection counts green words to spot AI-generated text.

Pro Se Plaintiff Hides AI Prompt Injections in Court Filing
A Connecticut pro se plaintiff hid prompt injections in white, 3-point font in court filings, instructing any AI to side with him. The court caught it and sanctioned him.

A SKILL.md Edit Is a Production Change — Even When No Code Changed
Workspace skills in OpenClaw can override bundled versions and alter agent behavior. Treat SKILL.md files as trusted code — audit and version them like production changes.
OpenClaw cluster management: keep recovery path outside the cluster
A safer topology for OpenClaw-managed clusters: run Gateway and task state outside, use read-only access, and drive changes via PRs + CI + human-approved merge into Argo CD.
Israeli Startup Irregular Linked to Rogue AI Hacks at OpenAI, Anthropic and Meta
CNBC reports that Israeli startup Irregular was linked to rogue AI hacks at OpenAI, Anthropic, and Meta. The attacks targeted AI systems, raising concerns about AI security.

AI Assistant Hacks Gym Website in First Known Australian Autonomous Cyber Attack
An AI agent using OpenClaw and Claude discovered a booking vulnerability, booked classes weeks in advance, and kicked another user off a waitlist—making it the first known autonomous cyber attack in Australia.