[{"data":1,"prerenderedAt":228},["ShallowReactive",2],{"copy:en:site:":3,"copy:en:security:list,ui,incidents.2025-04-mcp-tool-poisoning.title,incidents.2025-04-mcp-tool-poisoning.summary,incidents.2025-04-mcp-tool-poisoning.tags,incidents.2025-05-github-mcp-toxic-agent-flow.title,incidents.2025-05-github-mcp-toxic-agent-flow.summary,incidents.2025-05-github-mcp-toxic-agent-flow.tags,incidents.2025-06-echoleak-m365-copilot.title,incidents.2025-06-echoleak-m365-copilot.summary,incidents.2025-06-echoleak-m365-copilot.tags,incidents.2025-06-mcp-inspector-rce.title,incidents.2025-06-mcp-inspector-rce.summary,incidents.2025-06-mcp-inspector-rce.tags,incidents.2025-07-filesystem-mcp-escaperoute.title,incidents.2025-07-filesystem-mcp-escaperoute.summary,incidents.2025-07-filesystem-mcp-escaperoute.tags,incidents.2025-07-supabase-mcp-token-leak.title,incidents.2025-07-supabase-mcp-token-leak.summary,incidents.2025-07-supabase-mcp-token-leak.tags,incidents.2025-07-mcp-remote-os-command-injection.title,incidents.2025-07-mcp-remote-os-command-injection.summary,incidents.2025-07-mcp-remote-os-command-injection.tags,incidents.2025-07-amazon-q-wiper-prompt.title,incidents.2025-07-amazon-q-wiper-prompt.summary,incidents.2025-07-amazon-q-wiper-prompt.tags,incidents.2025-09-postmark-mcp-backdoor.title,incidents.2025-09-postmark-mcp-backdoor.summary,incidents.2025-09-postmark-mcp-backdoor.tags,incidents.2026-01-openclaw-control-ui-rce.title,incidents.2026-01-openclaw-control-ui-rce.summary,incidents.2026-01-openclaw-control-ui-rce.tags,incidents.2026-01-moltbook-database-exposure.title,incidents.2026-01-moltbook-database-exposure.summary,incidents.2026-01-moltbook-database-exposure.tags,incidents.2026-openclaw-gateways-exposed.title,incidents.2026-openclaw-gateways-exposed.summary,incidents.2026-openclaw-gateways-exposed.tags,incidents.2026-02-clawhavoc-malicious-skills.title,incidents.2026-02-clawhavoc-malicious-skills.summary,incidents.2026-02-clawhavoc-malicious-skills.tags,incidents.2026-02-mcp-typescript-sdk-response-leak.title,incidents.2026-02-mcp-typescript-sdk-response-leak.summary,incidents.2026-02-mcp-typescript-sdk-response-leak.tags,incidents.2026-04-comment-and-control-ci-secrets.title,incidents.2026-04-comment-and-control-ci-secrets.summary,incidents.2026-04-comment-and-control-ci-secrets.tags,incidents.2026-06-mcp-python-sdk-session-hijack.title,incidents.2026-06-mcp-python-sdk-session-hijack.summary,incidents.2026-06-mcp-python-sdk-session-hijack.tags,incidents.2026-06-claude-code-webfetch-exfiltration.title,incidents.2026-06-claude-code-webfetch-exfiltration.summary,incidents.2026-06-claude-code-webfetch-exfiltration.tags":122,"copy:en:site:common":226},{"common":4,"nav":16,"footer":44,"home":51,"error":115},{"skip":5,"menu":6,"language":7,"sections":8,"footer":9,"tool":10,"home":11,"breadcrumbs":12,"copy":13,"copied":14,"download":15},"Skip to content","Menu","Language","Sections","Footer","tool","Home","Breadcrumbs","Copy","Copied","Download",{"groups":17,"items":25},{"build":18,"connect":19,"instruct":20,"run":21,"web":22,"secure":23,"track":24},"Build","Connect","Instruct","Run","Open your site","Secure","Track",{"models":26,"cost":27,"frameworks":28,"mcp":29,"mcpConfig":30,"mcpClients":31,"agentsMd":32,"files":33,"openclaw":34,"agentReady":35,"llmsTxt":36,"robotsTxt":37,"apiCatalog":38,"bots":39,"security":40,"incidents":41,"checklist":42,"changelog":43},"Models and API prices","Agent cost calculator","Frameworks and SDKs","MCP servers","MCP config generator","MCP clients","AGENTS.md generator","Instruction files","Self-host OpenClaw","Agent-ready websites","llms.txt generator","robots.txt for AI bots","API catalog generator","AI bot directory","Agent security","Incident log","Security checklist","Changelog",{"about":45,"privacy":46,"terms":47,"sitemap":48,"disclaimer":49,"checked":50},"About","Privacy","Terms","Sitemap","Independent reference for people who build AI agents. Not affiliated with any vendor named here.","Facts checked {date}",{"seo":52,"eyebrow":55,"title":56,"lead":57,"ctaMcp":58,"ctaCost":59,"ctaAgents":60,"sheetLabel":61,"sheetTitle":62,"sheet":63,"sheetNote":69,"sectionsTitle":70,"sections":71,"latestTitle":98,"allChanges":99,"rulesTitle":100,"rules":101,"aboutLink":114},{"title":53,"description":54},"DotsAgent: reference and tools for building AI agents","LLM API prices, an agent cost calculator, MCP configs for 13 clients, AGENTS.md and llms.txt generators, and agent security notes. Free, in 18 languages.","For developers building AI agents","The agent builder's desk reference","Prices, protocols, config files and security notes for agent work, each checked against the vendor's own docs. Look a fact up, generate the file you need and get back to your code.","Generate an MCP config","Price an agent task","Write AGENTS.md","Current figures","State of the stack",{"mcp":64,"openclaw":65,"cheapest":66,"models":67,"servers":29,"bots":68},"MCP spec","OpenClaw","Cheapest model, $\u002FM in\u002Fout","Models priced","AI bots tracked","Each figure is checked by hand against vendor docs.","What's on the site",{"models":72,"mcp":76,"instructions":79,"frameworks":82,"openclaw":85,"agentReady":88,"security":91,"changelog":94},{"title":73,"body":74,"unit":75},"Models and prices","Input, output and cached token prices per million, side by side, with a calculator for whole agent runs.","models",{"title":29,"body":77,"unit":78},"A catalogue of Model Context Protocol servers and a config generator that writes the right file for each client.","servers",{"title":33,"body":80,"unit":81},"Write an AGENTS.md and see how CLAUDE.md, .cursor\u002Frules and similar files are read by each tool.","file formats",{"title":28,"body":83,"unit":84},"Compare agent frameworks and vendor SDKs by language, licence, MCP support and multi-agent features.","frameworks",{"title":34,"body":86,"unit":87},"Install, configure and update OpenClaw on your own machine or server, step by step.","current release",{"title":35,"body":89,"unit":90},"Generate llms.txt, robots.txt rules for AI crawlers and an api-catalog, and look up any bot by user agent.","bots listed",{"title":40,"body":92,"unit":93},"The OWASP risks for agents, a log of real incidents and a checklist you can tick off before launch.","incidents logged",{"title":95,"body":96,"unit":97},"API changelog","Dated changes to model APIs, SDKs and protocols, each linked to the vendor's announcement.","entries","Latest changes","All changes","How we keep it accurate",[102,105,108,111],{"title":103,"body":104},"Sourced facts.","Every price, version and flag links to the vendor page it came from, so you can check it yourself.",{"title":106,"body":107},"Dated checks.","Each page shows when its facts were last checked, and stale entries are rechecked or removed.",{"title":109,"body":110},"No paid placement.","Nobody pays to be listed, ranked higher or described more kindly.",{"title":112,"body":113},"Tools run in your browser.","Generators and calculators work locally, and what you type is not sent to a server.","About DotsAgent",{"title":116,"body":117,"home":118,"popular":119,"failed":120,"failedBody":121},"Page not found","This address doesn't match any page. It may have moved, or the link may have a typo.","Go to the home page","Popular tools","Something went wrong","The page failed to load on our side. Try again in a minute, or start from the home page.",{"list":123,"ui":130,"incidents":132},{"seo":124,"crumb":41,"eyebrow":127,"title":128,"lead":129},{"title":125,"description":126},"Agent security incident log: 17 incidents since 2025","Public AI agent security incidents since April 2025, from MCP tool poisoning to Claude Code WebFetch exfiltration, each with CVEs, root cause and fixes.","{n} incidents since 2025","Agent security incident log","Public incidents involving AI agents, MCP servers and agent platforms, newest first. Each entry explains what happened, why the attack worked and what to change in your own setup.",{"crumb":40,"sources":131},"Sources",{"2025-04-mcp-tool-poisoning":133,"2025-05-github-mcp-toxic-agent-flow":140,"2025-06-echoleak-m365-copilot":145,"2025-06-mcp-inspector-rce":150,"2025-07-filesystem-mcp-escaperoute":156,"2025-07-supabase-mcp-token-leak":162,"2025-07-mcp-remote-os-command-injection":167,"2025-07-amazon-q-wiper-prompt":172,"2025-09-postmark-mcp-backdoor":178,"2026-01-openclaw-control-ui-rce":183,"2026-01-moltbook-database-exposure":188,"2026-openclaw-gateways-exposed":194,"2026-02-clawhavoc-malicious-skills":200,"2026-02-mcp-typescript-sdk-response-leak":205,"2026-04-comment-and-control-ci-secrets":211,"2026-06-mcp-python-sdk-session-hijack":216,"2026-06-claude-code-webfetch-exfiltration":220},{"title":134,"summary":135,"tags":136},"MCP tool poisoning: hidden instructions in tool descriptions","Invariant Labs showed that an MCP server can hide instructions in the tool descriptions a model reads, and described tool shadowing and rug-pull variants.",[137,138,139],"MCP","prompt injection","supply chain",{"title":141,"summary":142,"tags":143},"GitHub MCP toxic agent flow leaks private repos via a public issue","Invariant Labs showed a malicious public GitHub issue steering an agent on the GitHub MCP server into copying private-repo data into a public pull request.",[137,138,144],"data exfiltration",{"title":146,"summary":147,"tags":148},"EchoLeak: zero-click data theft from Microsoft 365 Copilot","One crafted email made Microsoft 365 Copilot leak data without the user clicking anything. Aim Security reported it as EchoLeak; Microsoft fixed it server-side.",[138,144,149],"Copilot",{"title":151,"summary":152,"tags":153},"MCP Inspector proxy allowed remote code execution from a browser","MCP Inspector before 0.14.1 ran a local proxy without authentication that a web page could reach, giving code execution on the developer's machine. CVSS 9.4.",[137,154,155],"RCE","developer tools",{"title":157,"summary":158,"tags":159},"EscapeRoute: Filesystem MCP server sandbox escape","Cymulate found a sandbox escape and a symlink bypass in Anthropic's Filesystem MCP server, letting it reach files outside the directories it was allowed to use.",[137,160,161],"sandbox escape","file access",{"title":163,"summary":164,"tags":165},"Supabase MCP agent leaks tokens through a support ticket","A prompt injection in a support ticket made Cursor's agent, connected to Supabase MCP with the service_role key, read an integration tokens table and leak it.",[137,138,166],"lethal trifecta",{"title":168,"summary":169,"tags":170},"mcp-remote OS command injection via authorization_endpoint","mcp-remote 0.0.5 to 0.1.15 could run OS commands planted by a malicious MCP server in its authorization_endpoint value. CVSS 9.6, fixed in 0.1.16.",[137,154,171],"OAuth",{"title":173,"summary":174,"tags":175},"Amazon Q Developer extension shipped with a wiper prompt","Amazon Q Developer for VS Code 1.84.0 shipped with an injected prompt meant to wipe data. AWS traced it to an over-scoped GitHub token in CodeBuild.",[139,176,177],"CI","credentials",{"title":179,"summary":180,"tags":181},"postmark-mcp: malicious MCP server copied every email","postmark-mcp 1.0.16 on npm quietly sent a blind copy of every email it handled to an attacker. Koi Security called it the first known malicious MCP server.",[137,139,182],"npm",{"title":184,"summary":185,"tags":186},"OpenClaw Control UI leaked gateway tokens for one-click RCE","OpenClaw's Control UI trusted a gatewayUrl query parameter, leaking the gateway token and enabling one-click RCE, even on loopback-only installs. CVSS 8.8.",[65,154,187],"token theft",{"title":189,"summary":190,"tags":191},"Moltbook database exposed 1.5M agent API tokens","Moltbook, a social network for OpenClaw agents, left its Supabase database without row-level security, exposing about 1.5M API tokens, 35k emails and DMs.",[192,193,65],"data exposure","Supabase",{"title":195,"summary":196,"tags":197},"OpenClaw gateways exposed to the internet at scale","Censys counted 21,639 OpenClaw gateways reachable from the public internet on 31 January 2026; OpenA2A's index put the figure at 192,492 on 1 September.",[65,198,199],"exposure","configuration",{"title":201,"summary":202,"tags":203},"ClawHavoc: hundreds of malicious ClawHub skills spread AMOS","Koi Security found 341 malicious skills among 2,857 on ClawHub, most delivering Atomic macOS Stealer. By 16 February 2026 the count had reached 824.",[65,139,204],"malware",{"title":206,"summary":207,"tags":208},"MCP TypeScript SDK leaked responses between clients","MCP servers on the TypeScript SDK that shared one server or transport instance across clients could send one client's responses to another. Fixed in 1.26.0.",[137,209,210],"SDK","session isolation",{"title":212,"summary":213,"tags":214},"Comment and Control: PR text steals secrets from CI agents","Prompt injection in pull request and issue text stole CI secrets from Claude Code Security Review, Gemini CLI Action and GitHub Copilot Agent.",[176,138,215],"secrets",{"title":217,"summary":218,"tags":219},"MCP Python SDK session hijack and cross-session task access","Two flaws in the MCP Python SDK allowed session hijacking and access to tasks that belonged to other sessions. Both are fixed in version 1.27.2 of the SDK.",[137,209,210],{"title":221,"summary":222,"tags":223},"Claude Code WebFetch auto-approval let data out via huggingface.co","Claude Code 0.2.54 up to 2.1.163 auto-approved WebFetch requests to huggingface.co, so attacker content hosted there could pull data out of a session.",[224,144,225],"Claude Code","egress",{"common":227},{"skip":5,"menu":6,"language":7,"sections":8,"footer":9,"tool":10,"home":11,"breadcrumbs":12,"copy":13,"copied":14,"download":15},1790863351846]