AgentsCVE-2026-27001 OpenClaw Working Directory Prompt InjectionGitHub Advisory·high signalXBlueskyLinkedInCopy linkDirectory paths with control chars break prompt structure and inject attacker instructions. Novel attack vector: filesystem paths as prompt injection vectors.SourceSource pageGitHub Advisory↳ Follow the threadStack layer / Follow-up threadSeed Is a Single-File Agent That Ships With Nothing and Grows Its Own Tools Into a self/ DirectoryGitHub / Hacker NewsStack layer / Threat patternOpenAI Agents SDK 0.22.0 redacts guardrail-blocked tool output from replayable state and rejects conflicting provider configGitHub (openai/openai-agents-python)Policy dependency / Stack layerClaude Agent SDK for Python 0.2.140 adds MCP 2.x in-process servers and a structured ResultError instead of exit code 1GitHub (anthropics/claude-agent-sdk-python)Stack layerA Go Tool Called 'Vomit' Pipes Claude 5's Output Through a Local 20B Model to Make It Readable, and 260 HN Comments Agreed With the PremiseGitHub / Hacker NewsPolicy dependency / Stack layerPlow Latch Launched an Adversarial LLM Gatekeeper That Sits Between Your Agent and Your MacProduct HuntStack layer / ContrastApache Maka enters incubation as a local-first agent workspace where the event log is the runtimeGitHub TrendingStack layer / Threat patternDockhand Shipped a Free Self-Hosted Docker Control Plane With CVE Scanning and 1Password/Vault Secret Injection Built InProduct HuntStack layer / ContrastCHAP Proposes Hash-Linked Envelopes So You Can Answer 'What Did the Agent Draft and Why Did We Approve It'GitHub / Hacker News