Autonomous AI “agents” that can execute shell commands, fetch URLs, and write files on developer endpoints are rapidly expanding the attack surface by blurring the line between data and code and by effectively acting as a high-privilege “insider” on a user’s machine. Reporting highlighted OpenClaw (formerly ClawdBot/Moltbot) as a fast-adopted open-source agent designed to run locally and proactively take actions on a user’s behalf, often requiring broad access to files, online services, and communications tools—conditions that increase the impact of prompt-injection, malicious instructions, and unsafe automation.
In response to these risks, the open-source project Sage introduced an “Agent Detection & Response (ADR)” interception layer that hooks into supported agent platforms (including Claude Code, Cursor/VS Code, and OpenClaw) to inspect and gate tool calls such as Bash commands, URL retrieval, and file writes before execution. Sage combines cloud reputation checks (malware/phishing/scam detection), local heuristics using YAML-based threat definitions, and supply-chain checks for npm/PyPI packages (e.g., registry existence, reputation, and age analysis), plus plugin scanning at session start; it also emphasizes a privacy model that keeps commands and file contents local while optionally sharing URL/package hashes with Gen Digital reputation services. Related research cited alongside the release reported 18,000+ internet-exposed OpenClaw instances and that ~15% of observed skills contained malicious instructions, underscoring the need for endpoint-style controls tailored to agent-driven actions.

Track how attackers are adapting to this technology.
5 events from the most recent confirmed update back to the earliest known activity.
Gen Digital and Gen Threat Labs released the open-source Sage project, which inserts a security layer between AI agents and the operating system to inspect and gate commands, URL fetches, file writes, and package or plugin activity.
AWS reported that a Russian-speaking threat actor used multiple commercial generative AI services to help compromise more than 600 FortiGate devices across over 55 countries.
Security research cited by Krebs and Help Net Security reported that internet-exposed OpenClaw web admin interfaces could leak full configuration files and credentials, and that a notable share of ClawHub/OpenClaw skills contained malicious instructions.
A supply-chain attack on the Cline AI coding assistant used a prompt injection delivered through a GitHub issue title to trigger installation of a rogue OpenClaw instance with full system access on thousands of machines.
The open-source autonomous AI assistant OpenClaw, previously known as ClawdBot/Moltbot, was released in November 2025 for local use with broad access to systems and online services.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.