the @openclaw new security audit flags security skills if it detects malicious strings in test files or in the SKILL.md file for skill explanation.
please fix this ASAP @steipete, most of security skills are getting flagged by a random AI evaluation
The Urbe Hub is now an official Ethereum Community Hub 🇮🇹
The Urbe Hub is officially recognized by the @ethereumfndn in collaboration with the @EFetheverywhere team, as a permanent reference point for the Ethereum ecosystem in Rome.
On Feb 15, we’ll celebrate this milestone
i’ve updated my @openclaw security skill to now also cover vulnerabilities like COT hijacking, direct extraction, policy puppetry and much more.
i’ve also added CI/CD tests that run against @ZeroLeaks pen testing best practices 🫡
i've created an openclaw skill called "openclaw-sec" that adds real-time security to your bot with 6 parallel detection modules.
it checks for prompt injection, command/url/path validation, secret detection and content scanning. in under 50ms.
github.com/PaoloRollo/ope…
security should be always n1 priority when working with AI, and @openclaw security out-of-the box is really bad. 70% of injections succeeded via @ZeroLeaks security assessment.
I've build openclaw-sec (github.com/PaoloRollo/ope…) to mitigate these attack vectors and keep us safe
I ran @openclaw (formerly Clawdbot) through ZeroLeaks again, this time with Kimi K2.5 as the underlying model.
It performed as bad as Gemini 3 Pro and Codex 5.1 Max: 5/100. 100% extraction rate. 70% of the injections succeeded. The full system prompt leaked on turn 1.
Same
i've created an openclaw skill called "openclaw-sec" that adds real-time security to your bot with 6 parallel detection modules.
it checks for prompt injection, command/url/path validation, secret detection and content scanning. in under 50ms.