frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Ask HN: If there has been no prompt injection, is it safe?

2•sayYayToLife•1h ago
As I use open claw I am concerned about prompt injection more than bad code. However I think I'm irrationally paranoid. I'm small fries I'm a single individual, someone actively trying to hack me is exploiting a multi-million dollar zero day and they're not doing that on me.

If we're thinking about accidentally deleting everything through a terminal command, I've yet to see this actually occur.

Deductively I can see all of the worst case scenarios with open claw. Inductively I've never seen it actually happen.

I find it a bit irrational to pretend that open claw is a genuine security risk.

The moment I see on Hacker News that someone got prompt injected, I think I'll be concerned. Until then I would need almost a lottery like chance to get hacked as the first person through prompt injection.

Comments

TheTaytay•1h ago
I think the more likely attack vector in OpenClaw is convincing it to install a malicious npm package or script, have that siphon all machine/env secrets, and then watch those secrets get abused. (Cloud API key -> crypto mining. Wallet key->theft. Npm credentials->worm publishes more copies of itself. GitHub key->more theft and malicious code upload. Email API key->IP theft and password reset on other systems) Almost all of this can be automated, so the attacker doesn’t have to know who you are.

It’s not targeted per se.

verdverm•45m ago
> I find it a bit irrational to pretend that open claw is a genuine security risk.

Except that it is an actual security risk, no pretending is needed. In general, agents expand the security surface and attack vectors, regardless of framework.

Your argument that it hasn't happened, therefore it doesn't exist is a well known cognitive bias.

See the Lethal Trifecta for one way in which security requires more thoughtfulness.

OpenSage: Self-Programming Agent Generation Engine

https://www.opensage-agent.ai/
1•handfuloflight•24s ago•0 comments

More precise elevation data for GraphHopper routing engine

https://www.graphhopper.com/blog/2026/03/23/more-precise-elevation-data-for-graphhopper/
1•karussell•1m ago•0 comments

Spiky Points of View from 2k hours of agentic engineering

https://arrowsmithlabs.com/blog/spovs-from-2000-hours-of-agentic-engineering
1•arrowsmith•2m ago•0 comments

Jensen Huang: Nvidia – The $4T Company & the AI Revolution | Lex Fridman Podcast

https://www.youtube.com/watch?v=vif8NQcjVf0
1•doppp•2m ago•0 comments

Show HN: Wire Memory – Persistent cross-session memory for Claude Code

https://github.com/usewire/wire-memory
1•jitpal•2m ago•0 comments

Are Chicago Leaders Funding a Revolving Door for Crime? [video]

https://www.youtube.com/watch?v=GyGl2tIzVR0
1•donsupreme•5m ago•0 comments

TypeScript 6.0

https://devblogs.microsoft.com/typescript/announcing-typescript-6-0/
2•DanRosenwasser•5m ago•0 comments

Huel bought by Danone for reported €1B

https://www.bbc.com/news/articles/czre7pl600go
3•stevekemp•5m ago•0 comments

When the Whole Is More Than the Sum of Its Parts

https://thesecondbestworld.substack.com/p/when-the-whole-is-more-than-the-sum
1•paulpauper•7m ago•0 comments

Show HN: Behavioral analysis of your career decisions from your LinkedIn

https://coached.com/career-deep-read
1•rohanm93•7m ago•0 comments

Are Strings Still Our Best Hope for a Theory of Everything?

https://www.quantamagazine.org/are-strings-still-our-best-hope-for-a-theory-of-everything-20260323/
1•MindGods•7m ago•0 comments

Training LLMs to Predict World Events

https://thinkingmachines.ai/news/training-llms-to-predict-world-events/
1•enjeeneer•8m ago•0 comments

Zombies, AI, and the "Objective" Theory of Contracts [pdf]

https://download.ssrn.com/2026/3/12/6403619.pdf?response-content-disposition=inline&X-Amz-Securit...
1•droidjj•8m ago•0 comments

American Diner Gothic

https://www.thenewatlantis.com/publications/american-diner-gothic
1•jger15•8m ago•0 comments

Ray: The Free AI media player app that generates and translates subtitles

https://github.com/openai/whisper/discussions/2481
1•giamma•9m ago•0 comments

How to Do AI-Assisted Engineering

https://newsletter.eng-leadership.com/p/how-to-do-ai-assisted-engineering
1•sysoleg•9m ago•0 comments

Codex Subagents

https://developers.openai.com/codex/subagents
2•bootlegbilly•10m ago•0 comments

Gnoosic – Discover New Music

https://www.gnoosic.com/
1•nvalis•10m ago•0 comments

Hyperagents

https://arxiv.org/abs/2603.19461
1•handfuloflight•12m ago•0 comments

In a world of AI text, speech still reigns supreme

https://techxplore.com/news/2026-03-world-ai-text-speech-supreme.html
1•Brajeshwar•14m ago•0 comments

ContextCrush: The Context7 MCP Server Vulnerability Hiding in Plain Sight

https://noma.security/blog/contextcrush-context7-the-mcp-server-vulnerability/
1•tcbrah•14m ago•0 comments

The Mythical Agent-Month

https://www.oreilly.com/radar/the-mythical-agent-month/
1•sysoleg•15m ago•0 comments

Show HN: DocDrift – Use Tree-sitter and Local LLMs to fix stale documentation

1•AYSgood•15m ago•0 comments

Ask HN: Is Democracy a Control System?

2•motiw•16m ago•1 comments

x402: What if you never had to get an API key ever again?

https://stevekrouse.com/x402
1•goranmoomin•16m ago•0 comments

Package manager and web customizer for OpenSCAD

https://scadder.dev/
2•solderlocks•18m ago•1 comments

Show HN: I built a 0.07ms Python firewall to stop AI hallucinations

1•richardewing1•19m ago•1 comments

We're building an automated AI engineer, and it works

https://www.tensorzero.com/blog/automated-ai-engineer/
1•GabrielBianconi•20m ago•0 comments

What's New in Aspire 13.2

https://aspire.dev/whats-new/aspire-13-2/
1•doomroot13•23m ago•0 comments

Orbán's top opponent says Hungary's alleged Russian backchannel 'treason'

https://www.thetelegraph.com/news/world/article/orb-n-s-top-opponent-says-hungary-s-alleged-22091...
4•vrganj•24m ago•0 comments