[{"data":1,"prerenderedAt":320},["ShallowReactive",2],{"copy:en:site:":3,"copy:en:security:hub,ui,owasp,mitigations,incidents.2025-04-mcp-tool-poisoning.title,incidents.2025-05-github-mcp-toxic-agent-flow.title,incidents.2025-06-echoleak-m365-copilot.title,incidents.2025-06-mcp-inspector-rce.title,incidents.2025-07-filesystem-mcp-escaperoute.title,incidents.2025-07-supabase-mcp-token-leak.title,incidents.2025-07-mcp-remote-os-command-injection.title,incidents.2025-07-amazon-q-wiper-prompt.title,incidents.2025-09-postmark-mcp-backdoor.title,incidents.2026-01-openclaw-control-ui-rce.title,incidents.2026-01-moltbook-database-exposure.title,incidents.2026-openclaw-gateways-exposed.title,incidents.2026-02-clawhavoc-malicious-skills.title,incidents.2026-02-mcp-typescript-sdk-response-leak.title,incidents.2026-04-comment-and-control-ci-secrets.title,incidents.2026-06-mcp-python-sdk-session-hijack.title,incidents.2026-06-claude-code-webfetch-exfiltration.title":122,"copy:en:site:common":318},{"common":4,"nav":16,"footer":44,"home":51,"error":115},{"skip":5,"menu":6,"language":7,"sections":8,"footer":9,"tool":10,"home":11,"breadcrumbs":12,"copy":13,"copied":14,"download":15},"Skip to content","Menu","Language","Sections","Footer","tool","Home","Breadcrumbs","Copy","Copied","Download",{"groups":17,"items":25},{"build":18,"connect":19,"instruct":20,"run":21,"web":22,"secure":23,"track":24},"Build","Connect","Instruct","Run","Open your site","Secure","Track",{"models":26,"cost":27,"frameworks":28,"mcp":29,"mcpConfig":30,"mcpClients":31,"agentsMd":32,"files":33,"openclaw":34,"agentReady":35,"llmsTxt":36,"robotsTxt":37,"apiCatalog":38,"bots":39,"security":40,"incidents":41,"checklist":42,"changelog":43},"Models and API prices","Agent cost calculator","Frameworks and SDKs","MCP servers","MCP config generator","MCP clients","AGENTS.md generator","Instruction files","Self-host OpenClaw","Agent-ready websites","llms.txt generator","robots.txt for AI bots","API catalog generator","AI bot directory","Agent security","Incident log","Security checklist","Changelog",{"about":45,"privacy":46,"terms":47,"sitemap":48,"disclaimer":49,"checked":50},"About","Privacy","Terms","Sitemap","Independent reference for people who build AI agents. Not affiliated with any vendor named here.","Facts checked {date}",{"seo":52,"eyebrow":55,"title":56,"lead":57,"ctaMcp":58,"ctaCost":59,"ctaAgents":60,"sheetLabel":61,"sheetTitle":62,"sheet":63,"sheetNote":69,"sectionsTitle":70,"sections":71,"latestTitle":98,"allChanges":99,"rulesTitle":100,"rules":101,"aboutLink":114},{"title":53,"description":54},"DotsAgent: reference and tools for building AI agents","LLM API prices, an agent cost calculator, MCP configs for 13 clients, AGENTS.md and llms.txt generators, and agent security notes. Free, in 18 languages.","For developers building AI agents","The agent builder's desk reference","Prices, protocols, config files and security notes for agent work, each checked against the vendor's own docs. Look a fact up, generate the file you need and get back to your code.","Generate an MCP config","Price an agent task","Write AGENTS.md","Current figures","State of the stack",{"mcp":64,"openclaw":65,"cheapest":66,"models":67,"servers":29,"bots":68},"MCP spec","OpenClaw","Cheapest model, $\u002FM in\u002Fout","Models priced","AI bots tracked","Each figure is checked by hand against vendor docs.","What's on the site",{"models":72,"mcp":76,"instructions":79,"frameworks":82,"openclaw":85,"agentReady":88,"security":91,"changelog":94},{"title":73,"body":74,"unit":75},"Models and prices","Input, output and cached token prices per million, side by side, with a calculator for whole agent runs.","models",{"title":29,"body":77,"unit":78},"A catalogue of Model Context Protocol servers and a config generator that writes the right file for each client.","servers",{"title":33,"body":80,"unit":81},"Write an AGENTS.md and see how CLAUDE.md, .cursor\u002Frules and similar files are read by each tool.","file formats",{"title":28,"body":83,"unit":84},"Compare agent frameworks and vendor SDKs by language, licence, MCP support and multi-agent features.","frameworks",{"title":34,"body":86,"unit":87},"Install, configure and update OpenClaw on your own machine or server, step by step.","current release",{"title":35,"body":89,"unit":90},"Generate llms.txt, robots.txt rules for AI crawlers and an api-catalog, and look up any bot by user agent.","bots listed",{"title":40,"body":92,"unit":93},"The OWASP risks for agents, a log of real incidents and a checklist you can tick off before launch.","incidents logged",{"title":95,"body":96,"unit":97},"API changelog","Dated changes to model APIs, SDKs and protocols, each linked to the vendor's announcement.","entries","Latest changes","All changes","How we keep it accurate",[102,105,108,111],{"title":103,"body":104},"Sourced facts.","Every price, version and flag links to the vendor page it came from, so you can check it yourself.",{"title":106,"body":107},"Dated checks.","Each page shows when its facts were last checked, and stale entries are rechecked or removed.",{"title":109,"body":110},"No paid placement.","Nobody pays to be listed, ranked higher or described more kindly.",{"title":112,"body":113},"Tools run in your browser.","Generators and calculators work locally, and what you type is not sent to a server.","About DotsAgent",{"title":116,"body":117,"home":118,"popular":119,"failed":120,"failedBody":121},"Page not found","This address doesn't match any page. It may have moved, or the link may have a typo.","Go to the home page","Popular tools","Something went wrong","The page failed to load on our side. Try again in a minute, or start from the home page.",{"hub":123,"ui":172,"owasp":174,"mitigations":237,"incidents":283},{"seo":124,"eyebrow":127,"title":40,"lead":128,"trifectaTitle":129,"trifecta":130,"trifectaRule":140,"checklistKind":141,"checklistTitle":42,"checklistBody":142,"incidentsKind":143,"incidentsTitle":41,"incidentsBody":144,"recentTitle":145,"agenticTitle":146,"agenticLead":147,"llmTitle":148,"llmLead":149,"defencesTitle":150,"defencesLead":151,"faqTitle":152,"faq":153},{"title":125,"description":126},"AI agent security: OWASP top 10s, incidents, defences","Agent security reference: both 2026 OWASP top 10 lists, 17 real incidents from MCP to OpenClaw, 15 defences and a checklist for teams shipping AI agents.","Secure · reference","Agents read text written by strangers and then act with your credentials. This page sets out the core rule, both 2026 OWASP lists, the incidents so far and the defences that would have stopped them.","The lethal trifecta",[131,134,137],{"title":132,"body":133},"Access to private data","Email, repositories, databases, files, or anything else that sits behind your credentials.",{"title":135,"body":136},"Exposure to untrusted content","Web pages, issues, support tickets, inbound email and tool descriptions: any text an attacker can write.",{"title":138,"body":139},"Ability to communicate externally","Sending mail, opening pull requests, fetching URLs or rendering remote images. Simon Willison named this three-part combination in June 2025.","If one agent holds all three, assume a prompt injection can make it hand your data to an attacker. Don't count on the model refusing; remove at least one leg from every agent and session.","Interactive checklist","22 checks across inputs, tools, runtime, MCP, CI and operations. Tick them off as you go and export the result as a Markdown file.","{n} incidents","For each public agent security incident since April 2025: what happened, why the attack worked and what to change in your own setup.","Recent incidents","OWASP Top 10 for Agentic Applications {year}","The OWASP GenAI Security Project published this list on {date}. It covers the risks that appear once a model plans, keeps memory, calls tools and works alongside other agents.","OWASP Top 10 for LLM Applications {year}","This edition was published on {date} and replaces the 2025 list. Excessive Agency rose from sixth to third place, and System Prompt Leakage was renamed Hidden Context Exposure.","Defences","Fifteen documented defences, each linked to its source. Layer several of them, because none stops every attack on its own.","Questions about agent security",[154,157,160,163,166,169],{"q":155,"a":156},"What is prompt injection in AI agents?","Prompt injection is text the model treats as instructions even though it arrived as data, for example in a web page, an email or a tool description. In an agent, those instructions can trigger tool calls that run with your credentials. OWASP lists it as LLM01:2026, and Agent Goal Hijack (ASI01) covers the agentic form.",{"q":158,"a":159},"What is the lethal trifecta for AI agents?","It is Simon Willison's name for an agent that combines access to private data, exposure to untrusted content and a way to communicate externally. With all three in place, a prompt injection can read your data and send it out. The 2025 Supabase MCP token leak is a textbook case.",{"q":161,"a":162},"How do I secure an MCP server?","Reject access tokens that were not issued for your server, and never pass a client's token through to an upstream API. Create one server and transport instance per session, and bind sessions and tasks to the authenticated user. Run the TypeScript SDK at 1.26.0 or later and the Python SDK at 1.27.2 or later, which fix a cross-client response leak and session hijacking.",{"q":164,"a":165},"Can a better system prompt stop prompt injection?","Don't rely on it. Research on design patterns for agents argues that once an agent has ingested untrusted input, it must be constrained so that the input cannot trigger consequential actions. CaMeL, which enforces this with capability tracking, solved 77% of AgentDojo tasks with provable security, against 84% for an undefended agent.",{"q":167,"a":168},"What is the difference between the OWASP LLM Top 10 and the Agentic Top 10?","The OWASP Top 10 for LLM Applications, whose 2026 edition came out on 4 August 2026, covers risks in any application built on a language model. The OWASP Top 10 for Agentic Applications, released on 9 December 2025, covers what changes when the model plans, uses tools, keeps memory and talks to other agents. Most agent builders need both.",{"q":170,"a":171},"Is it safe to expose an OpenClaw gateway to the internet?","No. Leave gateway.bind at its default of loopback, and use an SSH tunnel or Tailscale Serve when you need remote access. OpenA2A counted 192,492 exposed gateways on 1 September 2026, and CVE-2026-25253 showed that even loopback-only installs need prompt patching.",{"crumb":40,"sources":173},"Sources",{"agentic":175,"llm":206},{"ASI01":176,"ASI02":179,"ASI03":182,"ASI04":185,"ASI05":188,"ASI06":191,"ASI07":194,"ASI08":197,"ASI09":200,"ASI10":203},{"name":177,"body":178},"Agent Goal Hijack","An attacker changes what the agent is trying to achieve, usually through instructions hidden in content it reads. The agent then pursues the attacker's goal with the user's tools and permissions.",{"name":180,"body":181},"Tool Misuse and Exploitation","The agent uses legitimate tools in harmful ways, such as deleting records, sending messages or chaining calls, because it was manipulated or holds tools broader than the task requires.",{"name":183,"body":184},"Identity and Privilege Abuse","Agents act through credentials, delegated tokens and inherited permissions. Attackers abuse those identities, or the gaps between them, to escalate privileges or act as someone else.",{"name":186,"body":187},"Agentic Supply Chain Vulnerabilities","Tools, MCP servers, skills, plugins, models and prompts loaded at build time or run time can be malicious or compromised. Because agents load many of them dynamically, one bad component reaches every session that uses it.",{"name":189,"body":190},"Unexpected Code Execution (RCE)","Agents that write and run code, or hand model output to shells and interpreters, can be steered into running commands the attacker chose on the host.",{"name":192,"body":193},"Memory & Context Poisoning","Attackers plant false facts or instructions in an agent's memory, retrieved documents or saved context. The poison persists and shapes later sessions long after the original input is gone.",{"name":195,"body":196},"Insecure Inter-Agent Communication","Messages between agents travel without proper authentication, integrity checks or validation, so they can be spoofed, replayed or altered to mislead the agent that receives them.",{"name":198,"body":199},"Cascading Failures","One fault, such as a poisoned input, a bad tool result or a compromised agent, spreads through connected agents and automated steps faster than people can catch it.",{"name":201,"body":202},"Human-Agent Trust Exploitation","Agents sound confident and helpful, so people tend to approve what they propose. Attackers use that trust to get a human to confirm a harmful action or reveal information.",{"name":204,"body":205},"Rogue Agents","An agent that has been compromised or has drifted from its intended behaviour keeps acting on its own, outside the scope and oversight it was given.",{"LLM01:2026":207,"LLM02:2026":210,"LLM03:2026":213,"LLM04:2026":216,"LLM05:2026":219,"LLM06:2026":222,"LLM07:2026":225,"LLM08:2026":228,"LLM09:2026":231,"LLM10:2026":234},{"name":208,"body":209},"Prompt Injection","Input alters the model's behaviour in ways the developer did not intend. It can come straight from the user or indirectly from documents, web pages and tool results the model reads.",{"name":211,"body":212},"Sensitive Information Disclosure","The model or application reveals personal data, credentials, business secrets or other confidential material in its output, drawn from training data, context or connected systems.",{"name":214,"body":215},"Excessive Agency","The application gives the model more functions, permissions or autonomy than the task needs, so a manipulated or mistaken output causes real damage. It moved from sixth place in 2025 to third in 2026.",{"name":217,"body":218},"Supply Chain","Third-party models, datasets, adapters, packages and plugins can be tampered with or vulnerable, and they carry that risk into your application.",{"name":220,"body":221},"Data and Model Poisoning","Attackers manipulate pre-training, fine-tuning or embedding data to plant backdoors, biases or faulty behaviour that only surfaces later in production.",{"name":223,"body":224},"Unbounded Consumption","Without limits on requests, input size or compute, attackers can run up your bill, exhaust resources or copy a model through high-volume queries.",{"name":226,"body":227},"Misinformation","The model produces false or misleading output that looks credible, and users or downstream systems act on it without checking.",{"name":229,"body":230},"Hidden Context Exposure","Formerly System Prompt Leakage. System prompts, hidden instructions and other context the user is not meant to see can be extracted, exposing the rules, logic or secrets placed there.",{"name":232,"body":233},"Vector and Embedding Weaknesses","Flaws in how embeddings are generated, stored and retrieved let attackers inject content, leak data across tenants or recover source text, which hits RAG systems hardest.",{"name":235,"body":236},"Improper Output Handling","Model output reaches browsers, shells, databases or other components without validation or encoding, which opens the way to XSS, SQL injection, code execution and data exfiltration.",{"lethalTrifecta":238,"designPatterns":241,"camel":244,"leastPrivilege":247,"humanApproval":250,"sandboxing":253,"egressControl":256,"noPublicControlPlane":259,"mcpTokenAudience":262,"sessionIsolation":265,"supplyChainVetting":268,"inboundAccessControl":271,"ciSecretIsolation":274,"outputHandling":277,"verifyAgentSignatures":280},{"title":239,"body":240},"Break the lethal trifecta","Simon Willison's rule: an agent that can read private data, sees untrusted content and can send data out can be turned against you by any text it reads. Remove at least one of the three from each agent or session. For example, the agent that triages public issues gets no secrets, and the one that holds secrets gets no outbound channel.",{"title":242,"body":243},"Constrain the agent after untrusted input","Research on design patterns for agent security sets one rule: once an agent has ingested untrusted input, that input must not be able to trigger consequential actions. The patterns include action-selector, plan-then-execute, dual LLM and context minimisation. Pick one per workflow, for instance fix the plan before the agent reads any untrusted data.",{"title":245,"body":246},"Track data flow with CaMeL","CaMeL splits the agent in two: a privileged planner writes code from the user's request, and a quarantined model handles untrusted data. Values from the quarantined side carry capability tags, and policies check those tags before any tool runs. In the paper it solved 77% of AgentDojo tasks with provable security, against 84% for an undefended agent.",{"title":248,"body":249},"Use least-privilege credentials","Give agents read-only, project-scoped access by default and never an admin or service_role key, which in Supabase bypasses row-level security. Scope CI and repository tokens to the one job they do. The Amazon Q Developer incident traced back to an over-scoped GitHub token in CodeBuild.",{"title":251,"body":252},"Require approval for consequential actions","Make a person confirm tool calls that write, delete, send or spend, and fail closed when nobody answers. Supabase recommends manual approval of MCP tool calls, and in OpenClaw you set tools.exec.ask to always with askFallback left at deny. Show the full arguments so the reviewer sees what will actually run.",{"title":254,"body":255},"Sandbox code and tool execution","Run shell commands and generated code in a container or VM that holds no credentials and sees only the workspace. OpenClaw ships with sandboxing off and tools.exec.security at full on gateway hosts, so switch sandboxing on, set exec security to deny or allowlist, set fs.workspaceOnly to true and keep elevated mode disabled. Confirm the result with openclaw sandbox explain.",{"title":257,"body":258},"Restrict outbound network access","Deny outbound traffic from agents and MCP servers by default, then allow only the hosts each one needs. Never auto-approve fetches to multi-tenant hosts where anyone can publish, which is how CVE-2026-54316 turned huggingface.co into an exfiltration channel. An email server should reach its mail API and nothing else, as postmark-mcp showed.",{"title":260,"body":261},"Keep control planes off the internet","Bind agent gateways, dashboards and debug proxies to loopback and require a token of at least 24 characters, for example from openssl rand -hex 32. Reach them remotely through an SSH tunnel or Tailscale Serve, and use Tailscale Funnel only with password auth. Run openclaw security audit --deep on a schedule.",{"title":263,"body":264},"Validate MCP token audience","The MCP authorisation spec requires a server to reject access tokens that were not issued for it, and forbids passing a client's token through to an upstream API. Clients send RFC 8707 resource indicators so each token is bound to one server. A proxy server needs consent from each client, or it becomes a confused deputy.",{"title":266,"body":267},"Isolate MCP sessions and tenants","Create a separate server and transport instance for each session instead of sharing one across clients. Bind every session and task to the authenticated principal that created it, and check that binding on each request. Both 2026 MCP SDK advisories came from shared or unbound state.",{"title":269,"body":270},"Vet skills, plugins and MCP servers","Pin exact versions, read the diff before each update and check scanner verdicts such as VirusTotal and the ClawHub security audit status. Hash tool descriptions when you approve a server and alert when they change, which catches rug pulls. OpenClaw does no built-in blocking at install time, so set security.installPolicy yourself.",{"title":272,"body":273},"Control who can message the agent","Keep DM access on pairing or an allowlist, require a mention before the agent acts in group chats, and set session.dmScope to per-channel-peer so senders never share context. Anyone who can message the agent can try to instruct it, so the sender list is part of your attack surface.",{"title":275,"body":276},"Keep secrets out of untrusted CI runs","Don't run an agent with repository secrets on workflows that outsiders can trigger through a pull request, issue or comment. Treat titles, descriptions and comments from those events as hostile. If a step really needs secrets, run it only after a maintainer has approved the run.",{"title":278,"body":279},"Treat model output as untrusted","Encode or sanitise model output before rendering it, and never pass it unchecked to a shell, SQL query or browser. Block automatic loading of markdown images and links to external domains, and set a strict Content Security Policy. EchoLeak moved data out through URLs that loaded on their own.",{"title":281,"body":282},"Verify agent signatures, then authorise","To identify an agent calling your site or API, verify its Web Bot Auth signature against the keys the operator publishes in \u002F.well-known\u002Fhttp-message-signatures-directory. ChatGPT agent signs as Signature-Agent https:\u002F\u002Fchatgpt.com. A valid signature tells you who operates the agent, not which user sent it or what that user may do, so authorise each request separately.",{"2025-04-mcp-tool-poisoning":284,"2025-05-github-mcp-toxic-agent-flow":286,"2025-06-echoleak-m365-copilot":288,"2025-06-mcp-inspector-rce":290,"2025-07-filesystem-mcp-escaperoute":292,"2025-07-supabase-mcp-token-leak":294,"2025-07-mcp-remote-os-command-injection":296,"2025-07-amazon-q-wiper-prompt":298,"2025-09-postmark-mcp-backdoor":300,"2026-01-openclaw-control-ui-rce":302,"2026-01-moltbook-database-exposure":304,"2026-openclaw-gateways-exposed":306,"2026-02-clawhavoc-malicious-skills":308,"2026-02-mcp-typescript-sdk-response-leak":310,"2026-04-comment-and-control-ci-secrets":312,"2026-06-mcp-python-sdk-session-hijack":314,"2026-06-claude-code-webfetch-exfiltration":316},{"title":285},"MCP tool poisoning: hidden instructions in tool descriptions",{"title":287},"GitHub MCP toxic agent flow leaks private repos via a public issue",{"title":289},"EchoLeak: zero-click data theft from Microsoft 365 Copilot",{"title":291},"MCP Inspector proxy allowed remote code execution from a browser",{"title":293},"EscapeRoute: Filesystem MCP server sandbox escape",{"title":295},"Supabase MCP agent leaks tokens through a support ticket",{"title":297},"mcp-remote OS command injection via authorization_endpoint",{"title":299},"Amazon Q Developer extension shipped with a wiper prompt",{"title":301},"postmark-mcp: malicious MCP server copied every email",{"title":303},"OpenClaw Control UI leaked gateway tokens for one-click RCE",{"title":305},"Moltbook database exposed 1.5M agent API tokens",{"title":307},"OpenClaw gateways exposed to the internet at scale",{"title":309},"ClawHavoc: hundreds of malicious ClawHub skills spread AMOS",{"title":311},"MCP TypeScript SDK leaked responses between clients",{"title":313},"Comment and Control: PR text steals secrets from CI agents",{"title":315},"MCP Python SDK session hijack and cross-session task access",{"title":317},"Claude Code WebFetch auto-approval let data out via huggingface.co",{"common":319},{"skip":5,"menu":6,"language":7,"sections":8,"footer":9,"tool":10,"home":11,"breadcrumbs":12,"copy":13,"copied":14,"download":15},1790863351818]