PROMPT INJECTION
Prompt injection moved downstream
Retrieval, orchestration, and hidden instructions are the new weak point.
Read full briefAI SECURITY BRIEF
Weekly research on exploit paths, exposed surfaces, and what stops risky AI from shipping.
Read by AI teams at companies building real systems.
how the break works
what is reachable now
what should stop release
THIS WEEK
Real attack paths. No fluff. Actionable in 5 minutes.
PROMPT INJECTION
Retrieval, orchestration, and hidden instructions are the new weak point.
Read full briefTOOL ABUSE
Fetch, shell, subprocess, and connectors decide how far a prompt can go.
Browse archivePUBLIC EXPOSURE
OpenClaw shows which endpoints, docs, and agent interfaces are reachable now.
Open watchboardTHREAT SURFACE
The surfaces where AI risk becomes reachable.
CURRENT TRACKING
Instruction override, hidden tool calls, indirect poisoning, and retrieval chains.
Shell execution, downloader chains, connector misuse, and runtime permissions.
Leaked API keys, unsafe logs, public config artifacts, and long-lived credentials.
Open docs, unauthenticated endpoints, and exposed agent interfaces.
PROOF LAYER
OpenClaw turns findings into a live board: target, issue, status.
INFRASTRUCTURE
The same evidence powers scanning, policy, and release control.
NEWSLETTER
Weekly research on AI exploit paths, exposed surfaces, and ship risk.
WeeklyCONTROL PLANE
Policy, scanning, and release decisions for AI systems.
AlphaSCANNER
Evidence-first scanning across repos, prompts, connectors, and surfaces.
Research-fedGATE
Release gates for risky AI changes.
AlphaVERIFY
Detect AI-generated content across image, text, audio, and video.
Live