Security 9
- Your Agent Called the Wrong Agent — On Purpose
- Invisible Characters, Visible Damage
- When /pair approve Bypasses the Scope Guard
- When Your LLM Proxy Becomes the Attack Vector
- When a Sentinel Value Becomes a Real API Key
- When Your AI Agent Silently Goes Blind
- When Your Dashboard Leaks the Keys: A CVSS 9.0 Credential Exposure in OpenClaw
- Eight Critical Bugs, One Day: Anatomy of an AI Agent Security Audit
- The Invisible Attack: How CSS Can Hijack Your AI Agent