OpenA2A Blog

Insights, updates, and best practices for AI agent security and identity management

#openclaw#security#open-source

Securing OpenClaw: 6 Security Fixes Landed in Main

We contributed 6 security fixes to OpenClaw (205K+ stars). 4 PRs merged directly, 2 adopted by maintainers. Fixes cover credential redaction, code safety scanning, path traversal, file permissions, timing side-channels, and npm lifecycle attacks.

OpenA2A Team
February 17, 2026
Read More
#agent-identity#cryptography#ai-agents

How Do You Give an AI Agent a Verifiable, Auditable, Enforceable Identity?

AI agents are making decisions, calling APIs, and accessing sensitive data autonomously. But most have no real identity — just shared API keys and bearer tokens. Here's how to give every agent a cryptographic identity that's verifiable, auditable, and enforceable at runtime.

Abdel Fane
February 11, 2026
Read More
#openclaw#security#supply-chain

OpenClaw Merges Built-In Skill Security Scanner

PR #9806 merged 1,721 lines of code into OpenClaw (169K GitHub stars), adding a built-in skill security scanner that detects malicious patterns across 6 check categories before skills can execute. The scanner runs automatically at install and update time.

OpenA2A Team
February 6, 2026
Read More
#nhi#ai-agents#governance

Why Your NHI Strategy Doesn't Cover AI Agents

Traditional NHI platforms manage service accounts and API keys. But AI agents represent a fundamentally different class of non-human identity that requires purpose-built governance. Here's the gap in your NHI strategy.

Abdel Fane
February 2, 2026
Read More

Stay Updated on AI Agent Security

Subscribe to our newsletter for weekly insights, vulnerability alerts, and best practices

Ready to Secure Your AI Agents?

Get started with AIM and protect your AI infrastructure with just one line of code