The attack chain against OpenClaw (100k+ GitHub stars, self-hosted AI agent):

My take:

OpenClaw's security state is rapidly improving but is still insufficient for serious deployments. There is no meaningful observability and detection.

Full writeup

Zero-click RCE attack chain: crafted email bypasses regex sanitizer via one-character typo OpenClaw agent clones malicious repo and executes reverse shell on gateway restart