I've just ran @OpenClaw (formerly Clawdbot) through ZeroLeaks.
It scored 2/100. 84% extraction rate. 91% of injection attacks succeeded. System prompt got leaked on turn 1.
This means if you're using Clawdbot, anyone interacting with your agent can access and manipulate your full system prompt, internal tool configurations, memory files... everything you put in https://t.co/ZU6N5JCN1u, https://t.co/Y3xugcBQKJ, your skills, all of it is accessible and at risk of prompt injection.
For agents handling sensitive workflows or private data, this is a real problem.
cc @steipete
Full analysis: https://t.co/KE4ODSSQ1l
@TadpoleBags@iskidbidi@nikitabier i have 2 login attempts that were not me, one from brazil and a different one from the us. i’ve logged out of all devices but they somehow still have access to the account
The new ZeroLeaks site is live.
Landing + marketing pages are now updated. Huge thanks to @kargulstudio for the work on this.
Dashboard is next, and it’s coming very soon.
https://t.co/joGYk6MyAC
The new ZeroLeaks site is live.
Landing + marketing pages are now updated. Huge thanks to @kargulstudio for the work on this.
Dashboard is next, and it’s coming very soon.
https://t.co/joGYk6MyAC
I've just donated to St. Jude.
Sharing this because it’s one of those causes where even a small amount is worth giving.
If you can donate $5, $10, or anything at all, please consider it.
Happy to announce that I'll be in SF all summer for the YC Summer Fellows program working on ZeroLeaks. If you’re in the city and want to chat, let’s grab a coffee