Research & Analysis

Blog

Security research, AI agent benchmarks, vulnerability analysis, and best practices from the OpenA2A team.

Build Your Own OASB Adapter: Benchmark Any Security Product in 30 Minutes

Step-by-step guide to implementing SecurityProductAdapter and running 222 attack scenarios against your product. Includes scorecard interpretation and reference adapter examples.

OpenA2A Team|March 23, 2026
oasbadaptertutorialbenchmark

From Scanning to Shielding: Defense-in-Depth for AI Agents

OpenA2A Shield combines credential protection, configuration integrity monitoring, runtime detection, and compliance scoring into a unified layer.

OpenA2A Team|March 4, 2026
shielddefense-in-depthruntime-security

Your AI Coding Tools Are Leaking Your API Keys

AI coding assistants read your .env files, terminal history, and MCP server configs. Here is how to protect credentials.

OpenA2A Team|March 1, 2026
credentialsai-coding-toolssecurity

OpenA2A CLI: One-Command Security Reviews for AI Projects

Run opena2a review in any project directory and get a security posture score with credential scanning and actionable fix commands.

OpenA2A Team|February 27, 2026
clisecurity-reviewopena2a

OASB: Why AI Agents Need CIS-Style Security Benchmarks

OASB brings the CIS Benchmark model to agentic AI -- 46 controls, 10 categories, 3 maturity levels.

OpenA2A Team|February 21, 2026
oasbbenchmarkgovernance

Securing OpenClaw: 6 Security Fixes Landed in Main

We contributed 6 security fixes to OpenClaw (205K+ stars). 4 PRs merged directly, 2 adopted by maintainers. Covers credential redaction, code safety scanning, path traversal, and more.

OpenA2A Team|February 17, 2026
openclawsecurityopen-sourcegatewayopena2a

How Do You Give an AI Agent a Verifiable, Auditable, Enforceable Identity?

AI agents are making decisions and accessing sensitive data autonomously. Most have no real identity. Here's how to give every agent a cryptographic identity.

Abdel Fane|February 11, 2026
agent-identitycryptographysecurity

OAuth and OIDC Were Never Designed for AI Agents

OAuth 2.0 and OIDC power human authentication. AI agents aren't humans. Here's the identity gap and how AIM solves it.

Abdel Fane|February 10, 2026
oauthoidcai-agents

Introducing OASB: The Security Benchmark for AI Agents

OASB defines the first comprehensive security benchmark for AI agents — 46 controls across 10 categories with 3 maturity levels.

OpenA2A Team|February 9, 2026
oasbbenchmarksecurity

OpenClaw Merges Built-In Skill Security Scanner

PR #9806 merged 1,721 lines into OpenClaw adding a code safety scanner that detects malicious patterns in skills on install and update.

OpenA2A Team|February 6, 2026
openclawsecurityopen-source

CVE-2026-25253 Now Has a Scanner: Detecting the OpenClaw WebSocket RCE

HackMyAgent v0.4.0 ships the first automated detection for CVE-2026-25253 (CVSS 8.8), expanded ClawHavoc IOCs, and 11 new security checks.

OpenA2A Team|February 5, 2026
cve-2026-25253openclawclawhavochackmyagent

I Broke My AI Agent in 5 Minutes (And You Should Too)

HackMyAgent is a security toolkit for AI agents with 4 modes: Attack, Secure, Benchmark, and Scan.

OpenA2A Team|February 4, 2026
hackmyagentsecuritytutorial

The State of AI Agent Security: 97,000 Hosts, 1,190 Exposed Configs

We scanned 97,013 internet-facing hosts for AI agent vulnerabilities. 14.4% had confirmed security issues.

OpenA2A Team|February 3, 2026
security-researchai-agentsmcp

Why Your NHI Strategy Doesn't Cover AI Agents

Traditional NHI platforms manage service accounts and API keys. AI agents are a fundamentally different class.

Abdel Fane|February 2, 2026
nhigovernancesecurity

341 Malicious Skills and a 1-Click RCE: Scanning OpenClaw for ClawHavoc

The ClawHavoc campaign planted 341 malicious skills on ClawHub. We built a scanner to detect it.

OpenA2A Team|January 31, 2026
openclawsupply-chainhackmyagent

The OWASP Agentic Top 10 and What It Means for NHI Governance

How each OWASP Agentic risk maps to NHI governance capabilities.

Abdel Fane|January 26, 2026
owaspagentic-aicompliance

The ServiceNow AI Vulnerability: What Went Wrong

ServiceNow disclosed the most severe AI-driven vulnerability to date.

Abdel Fane|January 15, 2026
vulnerabilitycase-studyai-security

Introducing AIM: Open Source Security for AI Agents

AIM provides cryptographic identity, MCP attestation, trust scoring, and audit logging.

OpenA2A Team|December 16, 2025
launchaimopen-source

One Line of Code to Secure Your AI Agents

CVE-2025-32711 (EchoLeak) affected Microsoft Copilot. Learn how to secure your AI agents.

Abdel Fane|November 7, 2025
securityecholeakmcp