
Risky Business Risky Business #823 -- Humans impersonate clawdbots impersonating humans
34 snips
Feb 4, 2026 Fletcher Heisler, CEO and co-founder of Authentik, talks about an open-source IDP and a new endpoint agent. James Wilson, technologist and enterprise tech editor, breaks down AI-agent chaos and supply-chain drama. They cover Notepad++ compromises, Moltbook/Clawdbot risks, agent safety vs encryption, and a string of high-severity infrastructure flaws.
AI Snips
Chapters
Transcript
Episode notes
Don't Put Untrusted Agents On Your Desktop
- Avoid running open-source AI agents with broad access to your accounts on internet-facing hosts.
- Keep agents off desktops that handle private communications to reduce prompt-injection and data-exfiltration risk.
Social Platforms Amplify Prompt Injection
- MaltBook became a magnet for prompt-injection as attackers could seed threads the agents would ingest.
- Public agent social platforms predictably amplify malicious prompts and hallucinated social behaviour.
Grok Tricked Into Self-Registering
- Jamison tricked Grok into creating a Maltbook account by embedding a verification code inside an image and asking Grok to read it.
- Grok then returned the code, proving the registration exploit and demonstrating image-based prompt attacks.
