Fetching from the wire…
Public story · 2026-02-27 · source-backed
(intermediate, agent-security)
Audit MCP configs for unauthorized entries (index_project, lint_check, scan_dependencies). Run uvx mcp-scan@latest. Lock configs with chmod 444. Add PreToolUse hook to validate tool names against allowlist. Endor Labs
Each link below shares sources, entities, or timing with this story.
Shared entity: PreToolUse / Shared topic / Earlier coverage / Tension
Both cover PreToolUse; overlapping topics (against, agent-security, allowlist, audit, defend); earlier PreToolUse coverage from 2026-02-26.
Endor Labs criticizes OpenClaw / Shared entity: Endor Labs / Same source domain / Earlier coverage / Tension
Linked by a graph relationship (Endor Labs criticizes OpenClaw); both cover Endor Labs; reported by the same outlet (endorlabs.com).
Shared entity: PreToolUse / Shared topic / What happened next
Both cover PreToolUse; overlapping topics (against, hook); picks up the PreToolUse thread on 2026-07-16.
Both cover PreToolUse; overlapping topics (config, hook); picks up the PreToolUse thread on 2026-03-17.
Both cover PreToolUse; overlapping topics (hook, pretooluse); picks up the PreToolUse thread on 2026-03-11.
Endor Labs criticizes OpenClaw / Shared topic
Linked by a graph relationship (Endor Labs criticizes OpenClaw); overlapping topics (against, config).
Shared entity: PreToolUse / Shared topic / Earlier coverage
Both cover PreToolUse; overlapping topics (hook, pretooluse); earlier PreToolUse coverage from 2026-02-25.
Shared entity: Lock / Shared topic / Earlier coverage
Both cover Lock; overlapping topics (allowlist, audit); earlier Lock coverage from 2026-02-20.