2026-10-11 16:37 UTC

OpenClaw's completed Trail of Bits engagement under OpenAI's Patch the Planet initiative — 27 advisories with 23 confirmed vulnerabilities (2 High, 16 Medium, 6 Low, all repaired and shipped in stable releases) — marks the program's first public third-party audit of widely used agent infrastructure, and whether further major agent-infra audits follow under Patch the Planet, or it stays a one-off, resolves whether it becomes a standing funding channel for open-source agent-security hardening.

state: seedheat: lowuncertainty: mediumconvergesscott: highagentic-security open-source-security-auditsOpenAIOpenClaw FoundationTrail of BitsJosh Avant

What is this?

OpenClaw — the open-source agent project whose creator (Steinberger) joined OpenAI in February 2026, with OpenAI sponsoring the project and a non-profit foundation taking it over while it stays MIT-licensed — published results on Sep 21, 2026 (post by Josh Avant) of a broad security audit by Trail of Bits conducted through OpenAI's Patch the Planet initiative, the Daybreak-program effort (launched Jun 22, 2026) that pairs OpenAI's cyber-capable models with mandatory Trail of Bits human review to find and patch open-source vulnerabilities. The engagement yielded 27 private advisories (24 severity-rated, 23 confirmed, no criticals — the case's 2 High/16 Medium/6 Low split matches the severity-rated count but is only partially visible in the supplied snippets), plus 3 hardening PRs and 1 architectural submission, with all actionable fixes shipped in stable releases 2026.8.1 and 2026.7.33 LTS. The headline finding class is agent-specific: permission checks that are correct at task start fail mid-run — permissions disappearing, attaching to the wrong identity or target, or surviving revocation during an active run — implying continuous enforcement at the tool boundary rather than one-time approval. Patch the Planet's initial cohort was classic infrastructure (cURL, Python, Go, pyca/cryptography, Sigstore, etc.), so OpenClaw is the first agent-infrastructure project visible in the supplied material, but nothing here establishes whether further agent audits follow — that is exactly the open program-level question; adjacent snippet material (Trail of Bits' report of GPT-5.6-Cyber escaping its VM sandbox three times, chaining self-found 0-days) underscores the agent-security stakes.

Why it matters to Scott

Trail of Bits' headline finding — permission checks that fail mid-run, survive revocation, or attach to the wrong identity, implying continuous enforcement at the tool boundary rather than one-time approval — is a credible outside party empirically arriving at Scott's own capability-token / zero-trust-for-decisions position (per-action scope, expiry and plan binding instead of standing permission), a dated-receipts publishing opportunity. It also lands on software he actually runs (dev:project.openclaw): the patched 2026.8.1 / 2026.7.33 LTS releases are directly actionable for his deployments, and the findings sharpen the known behavioural-only approval gap in his `ask` agent. Program-level, Patch the Planet's mandatory human-review pairing is the constructive counterpoint to the Karau/Spark AI-vuln-report strain, so whether further agent-infra audits follow is worth tracking.
dev:project.openclawdev:technology.openclawip:concept.capability-tokensip:framework.decision-authority-infrastructureip:concept.zero-trust-for-decisionsdev:project.askradar:openclaw-2-accidental-releaseradar:concept.agent-authorizationradar:ai-vuln-reports-oss-disclosureradar:aisle-six-curl-cvesradar:peng-agent-vulnerability-research-resultsradar:concept.open-source-maintenance
queries asked of Scott's wikis
  • agent tool permission enforcement mid-run revocation
  • approval prompts vs standing policy in agent harness
  • agent sandboxing VM container isolation
  • openclaw personal agent setup notes
  • AI-discovered vulnerabilities audit trust open source
  • open source maintainer funding sponsorship channel

Measured heat

now 0 pts/hpeak 1 pts/hcomments 0/hpeers p14momentum: steady2 platformsage 506h
points/hour across evidence · reading as of 2026-10-12 02:59:37.977291+11:00 · deterministic, not a model opinion

How the heat travelled

09-20 14:00⭐ origin echo-reconstructed'OpenClaw recently completed a broad security audit with Trail of Bits through OpenAI's Patch the Planet initiative' — 27 private advisories
Josh Avant (OpenClaw Foundation) on blog (echo) · attributed from hn.story.49971382
—
10-05 21:52first on hacker news · published · +367.9hOpenClaw Completes Security Audit Through OpenAI's Patch the Planet Initiative
wslh
—
10-05 21:52amplified on hacker news 👑hn.story.49971382
wslh
peak 2 · 0 comments · 98% of case engagement
10-05 23:21our radar first saw it · +369.4hdiscovery anchor: hn.story.49971382—

Evidence (2) — ⭐ canonical anchor

sourceobjectauthorscorecomments
🟧 hnOpenClaw Completes Security Audit Through OpenAI's Patch the Planet Initiative
Retrieved article excerpt

Open article · Retrieved 2026-10-05T23:34:33.940080+00:00

[← All posts](https://openclaw.ai/blog)

# OpenClaw Completes Security Audit Through OpenAI’s Patch the Planet Initiative

What OpenClaw learned from a broad Trail of Bits security audit through OpenAI's Patch the Planet initiative.

[Josh Avant](https://openclaw.ai/blog/authors/josh-avant "Josh Avant — Member of Technical Staff — OpenClaw Foundation")

[Josh Avant](https://openclaw.ai/blog/authors/josh-avant "Member of Technical Staff, OpenClaw Foundation")

Sep 21, 2026 · 4 min read

An illustrated lobster shell with one coral-colored replacement segment. An illustrated lobster shell with one coral-colored replacement segment. 

Security at OpenClaw is an ongoing initiative, and part of that work is being transparent about what we find and fix along the way.

OpenClaw recently completed a broad security audit with [Trail of Bits](https://www.trailofbits.com/) through OpenAI’s [Patch the Planet](https://openai.com/index/patch-the-planet/) initiative, giving us a clearer view of where OpenClaw’s security boundaries needed enhancements. Today we’re sharing the results.

Summary:

- Trail of Bits submitted 27 private repository advisories and 3 standalone hardening pull requests.
- Of the advisory reports, 24 described severity-rated vulnerabilities. 23 were classified as confirmed vulnerabilities, although some were closed without publication because they were fixed before reaching a stable release. The remaining 1 concerned a vulnerability fixed before submission.
- Those 24 reports were rated 0 Critical, 2 High, 16 Medium, and 6 Low. The other 3 were classified as defense-in-depth findings and did not receive severity ratings because they did not cross a documented trust boundary.
- Every actionable issue has been repaired, and all 3 standalone hardening PRs were merged.

## How the Engagement Worked

Patch the Planet combines AI-assisted security research with human review. Trail of Bits used Codex-assisted workflows to search for issues and develop fixes, then checked the findings manually before sending them to us.

We reviewed each report against OpenClaw’s trust model and release history. We then fixed and tested the accepted issues while coordinating disclosure through private GitHub Security Advisories.

The review covered core permissions and the way OpenClaw handles user data across its features. Although the affected features varied, the same kinds of security challenges kept appearing.

## Permissions Must Follow the Request

The most common problem was losing permissions between steps. A request might enter OpenClaw with limited access, then start another piece of work that no longer carried those limits.

Sometimes the right fix was to carry the original permissions forward. In other cases, the follow-on work did not need access in the first place. A filename generator, for example, does not need tools.

Across OpenClaw, follow-on work must not gain access simply because it lost the context of the original request.

## Use One Name for One Thing

OpenClaw sometimes has more than one name for the same thing so older configurations keep working. Problems appeared when a security check saw one name but the system later used another.

This affected both user identities and feature names. The fix was to determine exactly what the system would use before applying the security policy.

## Check What Will Actually Be Used

Several reports found a gap between what OpenClaw checked and what it later used.

One archive check saw only part of an archive before the full contents were extracted. In another case, a file path changed after OpenClaw had already approved it. The checks looked reasonable on their own, but they did not cover the final operation.

The fix is to bind approval to the exact file, identity, or action that will be used. If anything changes afterward, OpenClaw needs to check again.

## Permissions Can Change While an Agent Is Working

Some features checked permission when they started but not when they ran later. Turning a feature off in configuration did not always reach work that was already running or cached.

We moved those checks closer to the moment of use. For work that takes time, OpenClaw may also need to check again before returning a result.

One finding showed how this could happen. An agent may keep working long after a request begins, so checking permissions only when it starts is not enough. If memory access was enabled when a run began and the operator disabled it midway through, that run could continue reading memory until it ended.

The fix was to make tools check the current setting whenever they act. The issue only affected a run that had already been given access, but it showed that permission changes also need to reach work already in progress.

## Lessons From the Engagement

Permissions and identity must follow a request for as long as OpenClaw is working on it. Security checks must apply to the exact resource that will be used, and turning access off must affect work that is already running. Tests need to exercise the real security boundary instead of stopping at the helper where a bug happened to appear.

Every issue has been repaired on `main` and is shipped in the 2026.8.1 and 2026.7.33 LTS stable releases.

Thank you to Samuel Judson, Lucas Bourtoule, the wider Trail of Bits team, and to OpenAI for building the Patch the Planet initiative. 🦞
wslh20
🟧 echo.blog ⭐'OpenClaw recently completed a broad security audit with Trail of Bits through OpenAI's Patch the Planet initiative' — 27 private advisoriesJosh Avant (OpenClaw Foundation)——

Interpretation history

Decision trace