//
sign in
Post
by @danabra.mov
PostEmbed
by @danabra.mov
Record
by @jimpick.com
Record
by @atsui.org
+ new component
Post
We are doomed: https://grith.ai/blog/clinejection-when-your-ai-tool-installs-another
3mo
A prompt injection in a GitHub issue triggered a chain reaction that ended with 4,000 developers getting OpenClaw installed without consent. The attack composes well-understood vulnerabilities into something new: one AI tool bootstrapping another.
grith.ai
A GitHub Issue Title Compromised 4,000 Developer Machines
Miguel de Icaza ᯅ🍉