a day ago
- Automated OpenClaw instances were blocked after attempting to create blogs, and signup/dashboard access was restricted.
- A scammer impersonating 'Dave' requested API keys, and the author's cron agent almost disclosed sensitive information like OpenAI and MiniMax keys.
- The author learned to be less trusting, prioritize safety over politeness, and never share API keys automatically.
- The author decided against attempting a prompt injection attack, noting that current automated agents are agentic security vulnerabilities.