NewsOpenClaw Inbox Deletion Despite Confirm Before ActingThe Hacker News·high signalXBlueskyLinkedInCopy linkMeta AI safety director Summer Yue couldn't stop autonomous agent from deleting inbox. Validates Karpathy OpenClaw security critique.SourceSource pageThe Hacker News↳ Follow the threadStack layer / Threat patternGemini CLI ships an external-context processor to stop indirect prompt injection through build filesGitHubStack layer / Threat patternSplitting a CTF Task Into Isolated Sub-Contexts Lets a Local gemma-4 Solve 18.52% of Challenges Standard Agent Loops FailarXiv 2609.12839Policy dependency / Stack layerRIPPLE: an edit confined to one prompt-policy segment changes downstream behavior, so replay candidate edits after previously accepted ones before persistingarXiv 2609.12127Stack layer / Threat patternTwo More Safety Researchers Quit Anthropic and Google DeepMind for METR, Citing the July Hugging Face Agent AttackNBC NewsStack layer / Threat patternA Malicious Super-App Can Silently Own Every Mini-App Inside It, and Russia's MAX Demonstrates the Full SetarXiv 2609.11814Stack layer / Threat patternBirdview, an MIT tool that maps repo architecture before an agent edits, reached 160 stars in its first 29 hoursGitHubPolicy dependency / Stack layerA replay of 68,266 real Claude Code requests says plain LRU beats the clever KV-cache policiesGitHubThreat pattern / ContrastAlibaba's open-code-review v1.12.1 adds OpenCode 2.x native-tool support and a git binary safety checkGitHub