[{"data":1,"prerenderedAt":200},["ShallowReactive",2],{"copy:en:site:":3,"copy:en:security:incident,ui,mitigations,incidents.2025-06-echoleak-m365-copilot,incidents.2025-06-mcp-inspector-rce.title,incidents.2025-05-github-mcp-toxic-agent-flow.title":122,"copy:en:site:common":198},{"common":4,"nav":16,"footer":44,"home":51,"error":115},{"skip":5,"menu":6,"language":7,"sections":8,"footer":9,"tool":10,"home":11,"breadcrumbs":12,"copy":13,"copied":14,"download":15},"Skip to content","Menu","Language","Sections","Footer","tool","Home","Breadcrumbs","Copy","Copied","Download",{"groups":17,"items":25},{"build":18,"connect":19,"instruct":20,"run":21,"web":22,"secure":23,"track":24},"Build","Connect","Instruct","Run","Open your site","Secure","Track",{"models":26,"cost":27,"frameworks":28,"mcp":29,"mcpConfig":30,"mcpClients":31,"agentsMd":32,"files":33,"openclaw":34,"agentReady":35,"llmsTxt":36,"robotsTxt":37,"apiCatalog":38,"bots":39,"security":40,"incidents":41,"checklist":42,"changelog":43},"Models and API prices","Agent cost calculator","Frameworks and SDKs","MCP servers","MCP config generator","MCP clients","AGENTS.md generator","Instruction files","Self-host OpenClaw","Agent-ready websites","llms.txt generator","robots.txt for AI bots","API catalog generator","AI bot directory","Agent security","Incident log","Security checklist","Changelog",{"about":45,"privacy":46,"terms":47,"sitemap":48,"disclaimer":49,"checked":50},"About","Privacy","Terms","Sitemap","Independent reference for people who build AI agents. Not affiliated with any vendor named here.","Facts checked {date}",{"seo":52,"eyebrow":55,"title":56,"lead":57,"ctaMcp":58,"ctaCost":59,"ctaAgents":60,"sheetLabel":61,"sheetTitle":62,"sheet":63,"sheetNote":69,"sectionsTitle":70,"sections":71,"latestTitle":98,"allChanges":99,"rulesTitle":100,"rules":101,"aboutLink":114},{"title":53,"description":54},"DotsAgent: reference and tools for building AI agents","LLM API prices, an agent cost calculator, MCP configs for 13 clients, AGENTS.md and llms.txt generators, and agent security notes. Free, in 18 languages.","For developers building AI agents","The agent builder's desk reference","Prices, protocols, config files and security notes for agent work, each checked against the vendor's own docs. Look a fact up, generate the file you need and get back to your code.","Generate an MCP config","Price an agent task","Write AGENTS.md","Current figures","State of the stack",{"mcp":64,"openclaw":65,"cheapest":66,"models":67,"servers":29,"bots":68},"MCP spec","OpenClaw","Cheapest model, $\u002FM in\u002Fout","Models priced","AI bots tracked","Each figure is checked by hand against vendor docs.","What's on the site",{"models":72,"mcp":76,"instructions":79,"frameworks":82,"openclaw":85,"agentReady":88,"security":91,"changelog":94},{"title":73,"body":74,"unit":75},"Models and prices","Input, output and cached token prices per million, side by side, with a calculator for whole agent runs.","models",{"title":29,"body":77,"unit":78},"A catalogue of Model Context Protocol servers and a config generator that writes the right file for each client.","servers",{"title":33,"body":80,"unit":81},"Write an AGENTS.md and see how CLAUDE.md, .cursor\u002Frules and similar files are read by each tool.","file formats",{"title":28,"body":83,"unit":84},"Compare agent frameworks and vendor SDKs by language, licence, MCP support and multi-agent features.","frameworks",{"title":34,"body":86,"unit":87},"Install, configure and update OpenClaw on your own machine or server, step by step.","current release",{"title":35,"body":89,"unit":90},"Generate llms.txt, robots.txt rules for AI crawlers and an api-catalog, and look up any bot by user agent.","bots listed",{"title":40,"body":92,"unit":93},"The OWASP risks for agents, a log of real incidents and a checklist you can tick off before launch.","incidents logged",{"title":95,"body":96,"unit":97},"API changelog","Dated changes to model APIs, SDKs and protocols, each linked to the vendor's announcement.","entries","Latest changes","All changes","How we keep it accurate",[102,105,108,111],{"title":103,"body":104},"Sourced facts.","Every price, version and flag links to the vendor page it came from, so you can check it yourself.",{"title":106,"body":107},"Dated checks.","Each page shows when its facts were last checked, and stale entries are rechecked or removed.",{"title":109,"body":110},"No paid placement.","Nobody pays to be listed, ranked higher or described more kindly.",{"title":112,"body":113},"Tools run in your browser.","Generators and calculators work locally, and what you type is not sent to a server.","About DotsAgent",{"title":116,"body":117,"home":118,"popular":119,"failed":120,"failedBody":121},"Page not found","This address doesn't match any page. It may have moved, or the link may have a typo.","Go to the home page","Popular tools","Something went wrong","The page failed to load on our side. Try again in a minute, or start from the home page.",{"incident":123,"ui":128,"mitigations":130,"incidents":176},{"crumb":41,"whatTitle":124,"whyTitle":125,"doTitle":126,"toChecklist":127},"What happened","Why it worked","What to do","Work through the security checklist",{"crumb":40,"sources":129},"Sources",{"lethalTrifecta":131,"designPatterns":134,"camel":137,"leastPrivilege":140,"humanApproval":143,"sandboxing":146,"egressControl":149,"noPublicControlPlane":152,"mcpTokenAudience":155,"sessionIsolation":158,"supplyChainVetting":161,"inboundAccessControl":164,"ciSecretIsolation":167,"outputHandling":170,"verifyAgentSignatures":173},{"title":132,"body":133},"Break the lethal trifecta","Simon Willison's rule: an agent that can read private data, sees untrusted content and can send data out can be turned against you by any text it reads. Remove at least one of the three from each agent or session. For example, the agent that triages public issues gets no secrets, and the one that holds secrets gets no outbound channel.",{"title":135,"body":136},"Constrain the agent after untrusted input","Research on design patterns for agent security sets one rule: once an agent has ingested untrusted input, that input must not be able to trigger consequential actions. The patterns include action-selector, plan-then-execute, dual LLM and context minimisation. Pick one per workflow, for instance fix the plan before the agent reads any untrusted data.",{"title":138,"body":139},"Track data flow with CaMeL","CaMeL splits the agent in two: a privileged planner writes code from the user's request, and a quarantined model handles untrusted data. Values from the quarantined side carry capability tags, and policies check those tags before any tool runs. In the paper it solved 77% of AgentDojo tasks with provable security, against 84% for an undefended agent.",{"title":141,"body":142},"Use least-privilege credentials","Give agents read-only, project-scoped access by default and never an admin or service_role key, which in Supabase bypasses row-level security. Scope CI and repository tokens to the one job they do. The Amazon Q Developer incident traced back to an over-scoped GitHub token in CodeBuild.",{"title":144,"body":145},"Require approval for consequential actions","Make a person confirm tool calls that write, delete, send or spend, and fail closed when nobody answers. Supabase recommends manual approval of MCP tool calls, and in OpenClaw you set tools.exec.ask to always with askFallback left at deny. Show the full arguments so the reviewer sees what will actually run.",{"title":147,"body":148},"Sandbox code and tool execution","Run shell commands and generated code in a container or VM that holds no credentials and sees only the workspace. OpenClaw ships with sandboxing off and tools.exec.security at full on gateway hosts, so switch sandboxing on, set exec security to deny or allowlist, set fs.workspaceOnly to true and keep elevated mode disabled. Confirm the result with openclaw sandbox explain.",{"title":150,"body":151},"Restrict outbound network access","Deny outbound traffic from agents and MCP servers by default, then allow only the hosts each one needs. Never auto-approve fetches to multi-tenant hosts where anyone can publish, which is how CVE-2026-54316 turned huggingface.co into an exfiltration channel. An email server should reach its mail API and nothing else, as postmark-mcp showed.",{"title":153,"body":154},"Keep control planes off the internet","Bind agent gateways, dashboards and debug proxies to loopback and require a token of at least 24 characters, for example from openssl rand -hex 32. Reach them remotely through an SSH tunnel or Tailscale Serve, and use Tailscale Funnel only with password auth. Run openclaw security audit --deep on a schedule.",{"title":156,"body":157},"Validate MCP token audience","The MCP authorisation spec requires a server to reject access tokens that were not issued for it, and forbids passing a client's token through to an upstream API. Clients send RFC 8707 resource indicators so each token is bound to one server. A proxy server needs consent from each client, or it becomes a confused deputy.",{"title":159,"body":160},"Isolate MCP sessions and tenants","Create a separate server and transport instance for each session instead of sharing one across clients. Bind every session and task to the authenticated principal that created it, and check that binding on each request. Both 2026 MCP SDK advisories came from shared or unbound state.",{"title":162,"body":163},"Vet skills, plugins and MCP servers","Pin exact versions, read the diff before each update and check scanner verdicts such as VirusTotal and the ClawHub security audit status. Hash tool descriptions when you approve a server and alert when they change, which catches rug pulls. OpenClaw does no built-in blocking at install time, so set security.installPolicy yourself.",{"title":165,"body":166},"Control who can message the agent","Keep DM access on pairing or an allowlist, require a mention before the agent acts in group chats, and set session.dmScope to per-channel-peer so senders never share context. Anyone who can message the agent can try to instruct it, so the sender list is part of your attack surface.",{"title":168,"body":169},"Keep secrets out of untrusted CI runs","Don't run an agent with repository secrets on workflows that outsiders can trigger through a pull request, issue or comment. Treat titles, descriptions and comments from those events as hostile. If a step really needs secrets, run it only after a maintainer has approved the run.",{"title":171,"body":172},"Treat model output as untrusted","Encode or sanitise model output before rendering it, and never pass it unchecked to a shell, SQL query or browser. Block automatic loading of markdown images and links to external domains, and set a strict Content Security Policy. EchoLeak moved data out through URLs that loaded on their own.",{"title":174,"body":175},"Verify agent signatures, then authorise","To identify an agent calling your site or API, verify its Web Bot Auth signature against the keys the operator publishes in \u002F.well-known\u002Fhttp-message-signatures-directory. ChatGPT agent signs as Signature-Agent https:\u002F\u002Fchatgpt.com. A valid signature tells you who operates the agent, not which user sent it or what that user may do, so authorise each request separately.",{"2025-06-echoleak-m365-copilot":177,"2025-06-mcp-inspector-rce":194,"2025-05-github-mcp-toxic-agent-flow":196},{"title":178,"summary":179,"tags":180,"what":184,"why":187,"do":189},"EchoLeak: zero-click data theft from Microsoft 365 Copilot","One crafted email made Microsoft 365 Copilot leak data without the user clicking anything. Aim Security reported it as EchoLeak; Microsoft fixed it server-side.",[181,182,183],"prompt injection","data exfiltration","Copilot",[185,186],"EchoLeak, reported by Aim Security and tracked as CVE-2025-32711, was a zero-click data exfiltration flaw in Microsoft 365 Copilot. The attacker only had to send a crafted email. Once Copilot read that email while working for the user, its hidden instructions took effect.","The data left through URLs in Copilot's output that loaded automatically, so no click was needed. Microsoft fixed the issue on the server side.",[188],"Copilot combined private mailbox and document data, untrusted inbound email, and output that was rendered and fetched without user action. Auto-loaded images and links turned the model's answer into an outbound request that carried the data.",[190,191,192,193],"Don't auto-load images or links in model output that point to external domains.","Set a strict Content Security Policy on any page that renders model output.","Treat inbound email and shared documents as untrusted content, even inside your own tenant.","Keep agents that read external mail away from data the task doesn't need.",{"title":195},"MCP Inspector proxy allowed remote code execution from a browser",{"title":197},"GitHub MCP toxic agent flow leaks private repos via a public issue",{"common":199},{"skip":5,"menu":6,"language":7,"sections":8,"footer":9,"tool":10,"home":11,"breadcrumbs":12,"copy":13,"copied":14,"download":15},1790863351873]