PROMPT INJECTION
Prompt injection moved downstream
The weak point is often retrieval, orchestration, or hidden instructions.
SubscribeAI SECURITY BRIEF
Exploit paths, exposed surfaces, and ship risk for teams building AI.
Read it weekly. Act before the pattern spreads.
how the break works
what is reachable now
what should stop release
THIS WEEK
Short notes. Real attack paths. No security theater.
PROMPT INJECTION
The weak point is often retrieval, orchestration, or hidden instructions.
SubscribeTOOL ABUSE
Fetch, shell, subprocess, and connectors decide how far a prompt can go.
ArchivePUBLIC EXPOSURE
OpenClaw shows which endpoints, docs, and agent interfaces are reachable now.
WatchboardTHREAT SURFACE
The surfaces where AI risk becomes reachable.
CURRENT TRACKING
Instruction override, hidden tool calls, indirect poisoning, and retrieval chains.
Shell execution, downloader chains, connector misuse, and runtime permissions.
Leaked API keys, unsafe logs, public config artifacts, and long-lived credentials.
Open docs, unauthenticated endpoints, and exposed agent interfaces.
PROOF LAYER
OpenClaw turns findings into a live board: target, issue, status.
INFRASTRUCTURE
The same evidence powers scanning, policy, and release control.
NEWSLETTER
Weekly research on AI exploit paths, exposed surfaces, and ship risk.
WeeklyCONTROL PLANE
Policy, scanning, and release decisions for AI systems.
AlphaSCANNER
Evidence-first scanning across repos, prompts, connectors, and surfaces.
Research-fedGATE
Release gates for risky AI changes.
Alpha