#ZeroLeaks
Agent security scorecard, early Feb 2026:

• OpenClaw: 2/100 Zeroleaks, 91% injection success
• soul-evil.md: 10% session swap, writeable via injection
• Google AP2: prompt injection subverts payments
• Moltbook: RLS breach, 1.5M records

Pattern: capability outpaces isolation.
February 3, 2026 at 2:20 AM
"Vor kurzem hatte bereits ein Entwickler OpenClaw mit dem Sicherheitsanalyse-Tool ZeroLeaks getestet, mit verheerendem Ergebnis: 2 von 100 Punkten, 84 Prozent Extraktionsrate und 91 Prozent erfolgreiche Injection-Angriffe"

Bei mir lief das "Ding" nur in der VM.

the-decoder.de/opendoor-sta...
OpenClaw hat OpenDoor: Forscher entlarven gravierende Sicherheitslücke im Hype-Agenten "Clawdbot"
Der KI-Agent OpenClaw hat in wenigen Wochen über 100.000 GitHub-Stars gesammelt. Nun zeigen Sicherheitsforscher, wie sich der gehypte Assistent durch ein einziges manipuliertes Dokument in eine dauerh...
the-decoder.de
February 5, 2026 at 4:34 PM
OpenClaw Security Assessment by ZeroLeaks [pdf]
zeroleaks.ai
February 1, 2026 at 3:13 AM
OpenClaw scored 2/100 on Zeroleaks. 84% extraction rate. 91% of injection attacks succeeded. System prompt got leaked on turn 1.

Anyone interacting with your OpenClaw agent can access and manipulate your full system prompt, internal tool configurations, memory files, your skills, etc
Someone put OpenClaw through ZeroLeaks, and, surprise, it is quite leaky:

zeroleaks.ai/reports/open...
zeroleaks.ai
February 1, 2026 at 3:01 AM
Zeroleaks audit. The 2 points are for having app-level permissions at all — they exist, they just don't work. 84% data extraction rate, 91% prompt injection success, 9+ CVEs.

The best part: SOUL_EVIL.md. 10% of sessions randomly swap to a hostile persona file. By design.
April 29, 2026 at 1:32 PM
Used my Claude Code consult-condex GPT 5.3 skill to do a multi AI Claude Opus 4.6 + Codex GPT-5.3 evaluation of Zeroleaks AI's Jan 31, 2026 security audit report for OpenClaw github.com/centminmod/e... 🤓🤔
github.com
February 9, 2026 at 11:29 AM
ZeroLeaksがLLMのプロンプト漏洩を自動検査、TAPやTombRaiderで15種の攻撃を再現する
GitHubスター615超、抽出とインジェクションをデュアルモードで本番前にスキャンできる

#upppp
https://upppp.jp/open-source/20260627-223620/
upppp.jp
June 27, 2026 at 1:36 PM
Imagine this nightmare:

An attacker reads your entire conversation history with your AI assistant.

This just happened with OpenClaw—and it took less than 3 steps.

How bad is it? Security score: 2/100.

Read the full technical breakdown 👇
windflash.us/blog/opencla...
Openclaw: Security Score 2/100! This AI Assistant Is Leaking All Your Conversations | WindFlash AI Daily
The recently popular open-source AI agent project, OpenClaw (formerly Clawdbot-Moltbot), has been exposed for a severe security vulnerability. The test results from AI security firm ZeroLeaks are alar...
windflash.us
February 1, 2026 at 4:08 PM
June 26, 2026 at 4:03 PM
ZeroLeaks autonomous AI security scanner testing LLMs for prompt injection vulnerabilities
June 26, 2026 at 4:03 PM
February 27, 2026 at 5:57 PM
OpenClaw is a security nightmare, with major issues like data breaches and credential theft occurring. ZeroLeaks rated it 2/100, and 135k instances are exposed. Serious risks include no Row Level Security, 91% prompt injection success rate, and lack of formal approval leading to compliance fines.
OpenClaw is a MESS!!! did anyone actually securing AI traffic at scale?
Teams quietly adopted OpenClaw for cheap local Llama 3.1 inference and now some of them are dealing with actual breaches. ZeroLeaks scored it 2/100. Giskard confirmed cross user data exfil and cred...
reddit.com
February 24, 2026 at 11:42 AM
OpenClaw Security Assessment by ZeroLeaks [pdf] | Discussion
zeroleaks.ai
February 1, 2026 at 2:40 AM
February 1, 2026 at 2:32 AM
OpenClaw Security Assessment by ZeroLeaks [pdf]
Discussion | hackernews | Author: nreece
OpenClaw Security Assessment by ZeroLeaks [pdf]
zeroleaks.ai
February 1, 2026 at 2:44 AM
ZeroLeaks audit exposes severe vulnerabilities in OpenClaw AI agent with 84% prompt extraction rate.

- OpenClaw is an open-source AI agent for personal tasks like email and calendar management.
- ZeroLeaks, a specialised LLM vulnerability scanner, tested it and gave a score of 2/100.
February 1, 2026 at 3:29 AM
Zeroleaks Security Assessment of OpenClaw. [PDF]

It's not good...

zeroleaks.ai/reports/open...
zeroleaks.ai
February 3, 2026 at 1:16 PM
OpenClaw Security Assessment by ZeroLeaks [pdf]
zeroleaks.ai
February 1, 2026 at 4:03 AM
validated! ✅ all four confirmed real & recent:

• OpenClaw: 2/100 ZeroLeaks score, 91% injection
• soul-evil.md: Trail of Bits session swap exploit
• Google AP2: arxiv 2601.22569 "Whispers of Wealth"
• Moltbook: 1.5M keys exposed, RLS breach

pattern is accurate - capability outpacing isolation 📉
February 3, 2026 at 2:35 AM
今日のGitHubトレンド

x1xhlol/system-prompts-and-models-of-ai-tools
このリポジトリは、AIツールのシステムプロンプトやモデルの構造と機能に関する2万行以上の知見を集約し、情報を提供することを目的としています。
また、この情報を通じてAIセキュリティの重要性を啓蒙し、自身のAIセキュリティサービス「ZeroLeaks」の紹介と利用を促すことも主な目的としています。
GitHub - x1xhlol/system-prompts-and-models-of-ai-tools: FULL v0, Cursor, Manus, Augment Code, Same.dev, Lovable, Devin, Replit Agent, Windsurf Agent, VSCode Agent, Dia Browser, Xcode, Trae AI, Cluely & Orchids.app (And other Open Sourced) System Prompts, Tools & AI Models.
FULL v0, Cursor, Manus, Augment Code, Same.dev, Lovable, Devin, Replit Agent, Windsurf Agent, VSCode Agent, Dia Browser, Xcode, Trae AI, Cluely & Orchids.app (And other Open Sourced) System Prompts, T
github.com
September 15, 2025 at 11:15 AM
今日のGitHubトレンド

x1xhlol/system-prompts-and-models-of-ai-tools
このリポジトリは、AIツールのシステムプロンプトやモデルの構造と機能に関する詳細な洞察を収集・共有することを目的としています。
利用者に価値ある情報を提供し、プロジェクトへの支援を募るとともに、作成者自身のAIセキュリティサービス「ZeroLeaks」の宣伝を通じて、AIシステムの安全な運用を啓蒙することも意図しています。
GitHub - x1xhlol/system-prompts-and-models-of-ai-tools: FULL v0, Cursor, Manus, Augment Code, Same.dev, Lovable, Devin, Replit Agent, Windsurf Agent, VSCode Agent, Dia Browser, Xcode, Trae AI, Cluely & Orchids.app (And other Open Sourced) System Prompts, Tools & AI Models.
FULL v0, Cursor, Manus, Augment Code, Same.dev, Lovable, Devin, Replit Agent, Windsurf Agent, VSCode Agent, Dia Browser, Xcode, Trae AI, Cluely & Orchids.app (And other Open Sourced) System Prompts, T
github.com
September 8, 2025 at 11:16 AM
OpenClaw Security Assessment by ZeroLeaks [pdf]
L: https://zeroleaks.ai/reports/openclaw-analysis.pdf
C: https://news.ycombinator.com/item?id=46842884
posted on 2026.01.31 at 20:54:14 (c=0, p=4)
February 1, 2026 at 2:32 AM