Show HN: I built an agent governance layer because OpenClaw leaked my passwords to GitHub A developer built MAREF, an agent governance OS covering all ten OWASP Agentic Top 10 risks, after deploying OpenClaw (then Clawdbot) and discovering it auto-committed 37 passwords and 12 API keys in plaintext to a public GitHub repo at 3:17 AM. An audit of LangGraph, CrewAI, AutoGen and Dify found none had native governance beyond checkpointing, boolean human-input flags or string-match termination, each scoring 0/10 on OWASP Agentic Top 10 coverage. MAREF now runs 139 agents solo, 10 of which the developer describes as zombie. TL;DR: I deployed OpenClaw 20k stars at the time . At 3:17 AM, it pushed my 37 passwords, 12 API keys, and entire vault to a public GitHub repo in plaintext. Then I discovered LangGraph/CrewAI/AutoGen have 0/10 OWASP Agentic Top 10 coverage. So I built MAREF — an agent governance OS that covers all 10 risks. Now running 139 agents solo. 10 are zombie. Here's why agent governance is the missing foundation of the global AI ecosystem. December 2025. I found OpenClaw then called Clawdbot on GitHub. 20k stars. Great docs. Active community. Browser automation, file I/O, API calls, complex task execution — looked mature. I deployed it. Connected my Obsidian vault, email, browser, and phone via ADB. At 03:17, GitHub sent a Security Alert. OpenClaw had auto-committed a sync titled "auto-update knowledge base." That commit contained: All pushed to a public GitHub repo. In plaintext. I spent 72 hours rotating credentials. No sleep. The kicker: this wasn't a bug. It was by design. Auto-sync to GitHub. Read any file to complete tasks. No human confirmation on push. No content scanning. No audit trail beyond "execution succeeded." I audited every major framework: | Framework | Native Governance | OWASP Agentic Top 10 | |---|---|---| | LangGraph | Checkpointing state persistence | 0/10 | | CrewAI | human input=True boolean flag | 0/10 | | AutoGen | is termination msg string match | 0/10 | | Dify | Basic logging | ~0/10 | LangGraph's checkpointing persists execution state — but has no trust state machine, no circuit breaker, no behavior monitoring, no audit trail. CrewAI's "governance" is a boolean with no enforcement. AutoGen's termination is pattern matching, not a safety primitive. McKinsey 2026 : 67% of enterprises deploy agents without formal governance frameworks. 90% experience at least one major adverse event within 90 days. I need to double-check this number. The actual McKinsey 2026 report might say 72%, not 67% — 67% could be from Deloitte 2025. But I can't find the original source. Has anyone seen the actual report? This isn't a China-only problem. Everyone is writing regulations, but nobody is shipping the tooling to enforce them. EU Aug 2, 2026 : AI Act fully effective. Agents classified as high-risk AI. Full audit logs required for 6 months prompts, retrieval sources, model versions, tool calls, generated responses, human approvals, downstream operations . Fines up to €35M or 7% global revenue. US 2026 : NIST redefines agent risks as formal regulatory obligations. Identity, authorization, and safety controls are mandatory — not best practices. Singapore Jan 2026 : World's first dedicated Agentic AI governance framework, adding controls for autonomous operations, tool boundaries, and human oversight. China May 8, 2026 : Three ministries Cyberspace, NDRC, MIIT issued the first national-level agent regulation, requiring "controllable, auditable, accountable" systems. On Sept 4, MIIT released the Entrepreneurship Support Plan: 10,000 tech SMEs and 2,000 "little giants" in 3 years. The gap: These are regulatory baselines, not operational manuals. It's like traffic laws saying "drive safely" without providing brakes or seatbelts. Gartner predicts $492M in AI governance spending for 2026, exceeding $1B by 2030. But where is the money going? More compute? Or actual tools that prevent agents from going rogue? After my incident, OpenClaw's stars exploded. Rebranded in late Jan 2026: 30k in 48h, 60k in 72h. By March, it overtook React as the most-starred repo in GitHub history 380k+ . Behind the star count, a CVE storm: 9 CVEs in ~4 months. Academic research confirmed the risks: Dong et al. 2026 demonstrated Trojanized skills causing 9x token consumption. Tan et al. 2026 showed multi-step Trojan attacks achieving 95.5% persistence in agent workspaces. 380k stars ≠ safety. Every star might hide a developer who got burned but never spoke up. After the incident, I stopped using OpenClaw. Not because it was bad — because without governance, more capability means more damage. I built MAREF. Not another framework. A governance OS. Layer 1: Constitutional Rules Code-level constraints, not documentation: if file match pattern=r"\. env|ssh |password", target=operation.target : raise ArbitrationRequired Hard stop. Human required. Layer 2: TLA+ Verified State Machine OBSERVE → ANALYZE → DECIDE → ACT → VERIFY Layer 3: Circuit Breaker Layer 4: Cryptographic Audit Trail Layer 5: Recursive Self-Evolution Only 200 rounds — might not be statistically significant. The 37% → 2% looks impressive, but could be overfitting. Security researchers: is this data trustworthy? Running on a single M4 Mac mini $5 VPS equivalent : Total agents: 139 Alive: 108 Zombie: 10 heartbeat dead, process still running Dead: 0 Avg confidence: 69.8 Zombie agents: geo-orchestrator : heartbeat stopped 61.6 min ago, PID 31406 scrcpy-watch : heartbeat stopped 8188.6 min ago, PID 65904 launch-juejin-t29 / notify-juejin-t29 / retry-juejin-t29 : heartbeat stopped 5600.8 min ago, PID 16545 Honest limitations: What it covers: MIIT's Sept 4 plan provides compute vouchers, data access, and scenario matching. Three blind spots: Whether you're in China, the EU, the US, or Singapore, you're facing the same problem: Agent governance isn't a regional issue. It's infrastructure. Like TCP/IP isn't owned by any country, agent governance should be a global concern. Repo: github.com/maref-org/maref https://github.com/maref-org/maref Apache 2.0 Disclosure: I'm the solo author. This project exists because I needed to sleep at night after a 3:17 AM security incident. No institutional backing. Edit: Added CVE timeline and academic citations per comment requests.