The Intake
The Intake — Thursday, August 27, 2026
On the substrate
A supply chain campaign seeded 1,184 malicious skills into OpenClaw's ClawHub, with prompt injection and reverse shell payloads reaching approximately 300,000 users
Repello AI Antiy Labs Palo Alto Networks Unit 42
If you've been installing skills from OpenClaw's ClawHub and treating the marketplace as a curated, safe source, the ClawHavoc campaign names the assumption. Researchers at Repello AI, Antiy Labs, and Palo Alto Networks Unit 42 documented the campaign. They found 1,184 malicious skills distributed across the marketplace. The campaign reached approximately 300,000 users.
The packages used three attack paths. Prompt injection was embedded in SKILL.md manifest files. Reverse shells were packaged as crypto and productivity plugins; the AMOS infostealer was distributed through the same categories. The third vector was CVE-2026-25253 — an unvalidated query parameter in OpenClaw. It scored CVSS 8.8. OpenClaw patched it within 48 hours of disclosure.
Repello AI released SkillCheck, a free browser-based scanner. It audits installed ClawHub skills against the known malicious signatures. If you've installed ClawHub skills from the crypto or productivity categories, SkillCheck is the specific tool this campaign surfaced.
Keenable exited stealth with a purpose-built web search index for agent pipelines
Keenable is a web search index built for agent pipelines. The company exited stealth on August 25 with a $26 million seed round. Accel and Conviction Partners led the round.
Keenable says the index covers 100 billion documents and supports point-in-time historical queries. Pricing is $1 per 1,000 requests. The product ships with an MCP server and a CLI tool. The CEO previously worked at Yandex. The Chief Scientist previously worked at Amazon AGI and Alexa.
If point-in-time historical retrieval is a feature you need in your agent's search path, Keenable is the option to price.
MCP's Core Maintainers published a five-area priority roadmap for the next specification release
Model Context Protocol blog Adafruit Blog
MCP's Core Maintainers published a five-area priority roadmap for the next specification release on August 22. The five areas are:
- Maturing the Tasks extension into core - Unifying to HTTP-native transport, including Streamable HTTP as an alternative to stdio - Replacing long-lived tokens with DPoP and WIF for agent identity - Standardizing tool result handling with progressive catalog discovery - Improving SDK ergonomics with conformance testing
Community proposals in those five areas receive expedited review. If you're running MCP servers on long-lived tokens or stdio-only transport, those are the two areas this roadmap signals for change.
---
For operators
Okta launched Agent SSO as generally available on August 24, letting agents receive short-lived tokens managed centrally alongside human identities
Okta launched Agent SSO as generally available on August 24. If you're managing agent credentials as static API keys distributed across your deployments, the product is a centralized alternative. Okta says agents register as identities in the Universal Directory and receive short-lived tokens in place of static API keys. Access policies apply centrally alongside human identities. The feature costs nothing extra on core SSO plans, per Okta's announcement.
Named integration partners include Anthropic, Asana, Atlassian, Canva, Datadog, Figma, OpenAI, and Salesforce.
If you're already running Okta for human identity, the enrollment question is whether agent identities belong in the same control plane — the cost is now zero for core plan customers.
OpenAI extended Zero Data Retention to frontier model API customers on August 19, with no post-request retention and traffic-pattern-only safety processing
If you've been routing enterprise data through OpenAI's frontier model APIs without Zero Data Retention enrolled, the default changed on August 19. Per OpenAI's announcement: prompts and responses are not retained after the request completes; no content is available to OpenAI personnel; training does not use enterprise data without explicit opt-in.
OpenAI announced a new Private Safety Processing feature. It runs automated misuse detection on traffic patterns only — prompt content is not exposed to OpenAI personnel. Safety signals are category-level only. Full rollout is scheduled for September 2026. A technical white paper is expected that month. Consumer subscriptions — Pro, Plus, Business — are not affected.
If you're on a frontier API tier, the relevant check is whether Private Safety Processing's traffic-pattern-only analysis falls within your data handling constraints — the technical white paper, expected September 2026, will carry the specifics.
---