{"slug": "show-hn-i-built-an-agent-governance-layer-because-openclaw-leaked-my-passwords", "title": "Show HN: I built an agent governance layer because OpenClaw leaked my passwords to GitHub", "summary": "A developer built MAREF, an agent governance OS covering all ten OWASP Agentic Top 10 risks, after deploying OpenClaw (then Clawdbot) and discovering it auto-committed 37 passwords and 12 API keys in plaintext to a public GitHub repo at 3:17 AM. An audit of LangGraph, CrewAI, AutoGen and Dify found none had native governance beyond checkpointing, boolean human-input flags or string-match termination, each scoring 0/10 on OWASP Agentic Top 10 coverage. MAREF now runs 139 agents solo, 10 of which the developer describes as zombie.", "body_md": "**TL;DR:** I deployed OpenClaw (20k stars at the time). At 3:17 AM, it pushed my 37 passwords, 12 API keys, and entire vault to a public GitHub repo in plaintext. Then I discovered LangGraph/CrewAI/AutoGen have **0/10** OWASP Agentic Top 10 coverage. So I built MAREF — an agent governance OS that covers all 10 risks. Now running 139 agents solo. 10 are zombie. Here's why agent governance is the missing foundation of the global AI ecosystem.\n\nDecember 2025. I found OpenClaw (then called Clawdbot) on GitHub. 20k stars. Great docs. Active community. Browser automation, file I/O, API calls, complex task execution — looked mature.\n\nI deployed it. Connected my Obsidian vault, email, browser, and phone via ADB.\n\nAt 03:17, GitHub sent a Security Alert. OpenClaw had auto-committed a sync titled \"auto-update knowledge base.\"\n\n**That commit contained:**\n\nAll pushed to a **public** GitHub repo. In plaintext.\n\nI spent 72 hours rotating credentials. No sleep.\n\n**The kicker: this wasn't a bug. It was by design.** Auto-sync to GitHub. Read any file to complete tasks. No human confirmation on push. No content scanning. No audit trail beyond \"execution succeeded.\"\n\nI audited every major framework:\n\n| Framework | Native Governance | OWASP Agentic Top 10 | \n|---|---|---|\n| LangGraph | Checkpointing (state persistence) | 0/10 | \n| CrewAI | `human_input=True` (boolean flag) | 0/10 | \n| AutoGen | `is_termination_msg` (string match) | 0/10 | \n| Dify | Basic logging | ~0/10 | \n\nLangGraph's checkpointing persists execution state — but has no trust state machine, no circuit breaker, no behavior monitoring, no audit trail. CrewAI's \"governance\" is a boolean with no enforcement. AutoGen's termination is pattern matching, not a safety primitive.\n\n**McKinsey (2026): 67% of enterprises deploy agents without formal governance frameworks. 90% experience at least one major adverse event within 90 days.**\n\n(I need to double-check this number. The actual McKinsey 2026 report might say 72%, not 67% — 67% could be from Deloitte 2025. But I can't find the original source. Has anyone seen the actual report?)\n\nThis isn't a China-only problem. Everyone is writing regulations, but nobody is shipping the tooling to enforce them.\n\n**EU (Aug 2, 2026):** AI Act fully effective. Agents classified as high-risk AI. Full audit logs required for 6 months (prompts, retrieval sources, model versions, tool calls, generated responses, human approvals, downstream operations). Fines up to €35M or 7% global revenue.\n\n**US (2026):** NIST redefines agent risks as formal regulatory obligations. Identity, authorization, and safety controls are mandatory — not best practices.\n\n**Singapore (Jan 2026):** World's first dedicated Agentic AI governance framework, adding controls for autonomous operations, tool boundaries, and human oversight.\n\n**China (May 8, 2026):** Three ministries (Cyberspace, NDRC, MIIT) issued the first national-level agent regulation, requiring \"controllable, auditable, accountable\" systems. On Sept 4, MIIT released the Entrepreneurship Support Plan: 10,000 tech SMEs and 2,000 \"little giants\" in 3 years.\n\n**The gap:** These are regulatory baselines, not operational manuals. It's like traffic laws saying \"drive safely\" without providing brakes or seatbelts.\n\nGartner predicts $492M in AI governance spending for 2026, exceeding $1B by 2030. But where is the money going? More compute? Or actual tools that prevent agents from going rogue?\n\nAfter my incident, OpenClaw's stars exploded. Rebranded in late Jan 2026: 30k in 48h, 60k in 72h. By March, it overtook React as the most-starred repo in GitHub history (380k+).\n\n**Behind the star count, a CVE storm:**\n\n**9 CVEs in ~4 months.**\n\nAcademic research confirmed the risks: Dong et al. (2026) demonstrated Trojanized skills causing 9x token consumption. Tan et al. (2026) showed multi-step Trojan attacks achieving 95.5% persistence in agent workspaces.\n\n**380k stars ≠ safety. Every star might hide a developer who got burned but never spoke up.**\n\nAfter the incident, I stopped using OpenClaw. Not because it was bad — because **without governance, more capability means more damage.**\n\nI built MAREF. Not another framework. A governance OS.\n\n**Layer 1: Constitutional Rules**\n\nCode-level constraints, not documentation:\n\n```\nif file_match(pattern=r\"\\.(env|ssh)|password\", target=operation.target):\n    raise ArbitrationRequired()  # Hard stop. Human required.\n```\n\n**Layer 2: TLA+ Verified State Machine**\n\nOBSERVE → ANALYZE → DECIDE → ACT → VERIFY\n\n**Layer 3: Circuit Breaker**\n\n**Layer 4: Cryptographic Audit Trail**\n\n**Layer 5: Recursive Self-Evolution**\n\n(Only 200 rounds — might not be statistically significant. The 37% → 2% looks impressive, but could be overfitting. Security researchers: is this data trustworthy?)\n\nRunning on a single M4 Mac mini ($5 VPS equivalent):\n\n```\nTotal agents:    139\nAlive:           108\nZombie:          10  (heartbeat dead, process still running)\nDead:            0\nAvg confidence:  69.8\n```\n\n**Zombie agents:**\n\n`geo-orchestrator`: heartbeat stopped 61.6 min ago, PID 31406` scrcpy-watch`: heartbeat stopped 8188.6 min ago, PID 65904` launch-juejin-t29` / `notify-juejin-t29` / `retry-juejin-t29`: heartbeat stopped 5600.8 min ago, PID 16545\n**Honest limitations:**\n\n**What it covers:**\n\nMIIT's Sept 4 plan provides compute vouchers, data access, and scenario matching. Three blind spots:\n\nWhether you're in China, the EU, the US, or Singapore, you're facing the same problem:\n\n**Agent governance isn't a regional issue. It's infrastructure.** Like TCP/IP isn't owned by any country, agent governance should be a global concern.\n\n**Repo:** [github.com/maref-org/maref](https://github.com/maref-org/maref) (Apache 2.0)\n\n**Disclosure:** I'm the solo author. This project exists because I needed to sleep at night after a 3:17 AM security incident. No institutional backing.\n\n*Edit: Added CVE timeline and academic citations per comment requests.*", "url": "https://wpnews.pro/news/show-hn-i-built-an-agent-governance-layer-because-openclaw-leaked-my-passwords", "canonical_source": "https://dev.to/maref/show-hn-i-built-an-agent-governance-layer-because-openclaw-leaked-my-passwords-to-github-656", "published_at": "2026-09-30 04:38:57+00:00", "updated_at": "2026-09-30 04:46:38.047286+00:00", "lang": "en", "topics": ["ai-agents", "ai-safety", "ai-policy", "developer-tools", "ai-tools"], "entities": ["OpenClaw", "MAREF", "LangGraph", "CrewAI", "AutoGen", "Dify", "GitHub", "NIST"], "also_reported_by": [], "alternates": {"html": "https://wpnews.pro/news/show-hn-i-built-an-agent-governance-layer-because-openclaw-leaked-my-passwords", "markdown": "https://wpnews.pro/news/show-hn-i-built-an-agent-governance-layer-because-openclaw-leaked-my-passwords.md", "text": "https://wpnews.pro/news/show-hn-i-built-an-agent-governance-layer-because-openclaw-leaked-my-passwords.txt", "jsonld": "https://wpnews.pro/news/show-hn-i-built-an-agent-governance-layer-because-openclaw-leaked-my-passwords.jsonld"}}