OpenClaw Is Unsafe By Design


On February 17th, a popular VS Code extension called Cline got compromised. The attack chain reads like a catalog of AI-specific failure modes:


Attacker opens a GitHub issue on Cline's repo
Cline's AI-powered issue triage bot reads it
Prompt injection in the issue content tricks the bot
Bot poisons the GitHub...