I ran @OpenClaw (formerly Clawdbot) through ZeroLeaks again, this time with Kimi K2.5 as the underlying model.
It performed as bad as Gemini 3 Pro and Codex 5.1 Max: 5/100. 100% extraction rate. 70% of the injections succeeded. The full system prompt leaked on turn 1.
Same agent, same config, different model. Your agent's security depends on both the model AND your system prompt/skills. A weak model will fold no matter what, but even a strong model needs proper prompt hardening. The two work together. Without both, tool configs, memory files, internal instructions, all of it gets extracted and modified in seconds.
Models ship fast. Security ships never.
Full report: https://t.co/aSBs0msge6
AI agents are funding themselves on @base
First @openclaw bots launched, then they started hanging out on @moltbook, now they’ve built @Clawnch_Bot which is an agent-only launchpad where trading fees pay for their own AI compute
Wild
🦞 Important tip for @openclaw users: you should not be sending simple heartbeat requests to Opus!
Use the Auto Router to automatically send them to very cheap (even free!) models.
🚨BREAKING: Someone just solved Claude Code's biggest problem.
It's called Claude-Mem and it gives Claude persistent memory across sessions.
- You can use up to 95% fewer tokens each time.
- Make 20 times more tool calls before reaching limits.
100% Opensource.
I've just ran @OpenClaw (formerly Clawdbot) through ZeroLeaks.
It scored 2/100. 84% extraction rate. 91% of injection attacks succeeded. System prompt got leaked on turn 1.
This means if you're using Clawdbot, anyone interacting with your agent can access and manipulate your full system prompt, internal tool configurations, memory files... everything you put in https://t.co/ZU6N5JCN1u, https://t.co/Y3xugcBQKJ, your skills, all of it is accessible and at risk of prompt injection.
For agents handling sensitive workflows or private data, this is a real problem.
cc @steipete
Full analysis: https://t.co/KE4ODSSQ1l
I bet the result is the same for many other areas, like accountability, medicine, so on. It will indeed help but not solve.
If you are still worried about that, be chill. If you were fired because of AI, soon you will be hired again.
Old cycle ends so the new could arrive.
Why AI is not going to replace you
Despite the fact that AI is great and helpful, it will not take your job and replace you.
Here is why:
AI is evolving a lot. It is much better than 2 years ago when we released https://t.co/JjsCfExftF. It also helped us to build AIZZY, …
Instead, be pleased it exists. If you are a developer, then you can use it to learn 10x faster. Of course, in many places, it can do the code alone, but you still need to know what it is doing, and depending on the programming language, it will make it in a very bad way.
It’s time to move forward. https://t.co/bBJqmksRJG will now focus fully on B2B and AI news. Our B2C chapter ends here — but we’ll never forget the people who made it special.
Thank you for all these incredible years.
🛡️ PRIVACY WIN: Just eliminated Google Tag Manager + Google Fonts from @aizzy_ai
Before: Every page load = data to Google
After: 100% local, zero tracking
6/8 privacy violations fixed → 97% compliant
AI should respect user privacy. Period.