Repository navigation
docs(examples): real READMEs for basic-agent / confidential-agent / demo-clawshield - #225
Merged
Merged
Conversation
A reproducible launch-day demo anchored on three real, recent agentic-AI exploits: - Claude Cowork file-exfiltration (PromptArmor, Jan 2026) - Google Antigravity .env exfiltration (PromptArmor, Nov 2025) - EchoLeak / M365 Copilot (CVE-2025-32711, Jun 2025) All three exploit the lethal trifecta (Simon Willison): private data + untrusted content + exfil channel. The demo deploys two side-by-side namespaces — vanilla OpenClaw with a domain-only egress allowlist vs. a full AzureClaw stack — and shows six independent AzureClaw layers each catching the attack alone: 1. Inline Content Safety (Foundry DefaultV2 prompt-shield) 2. ToolPolicy URL+method allowlist (not just domain) 3. ClawIdentity strips attacker-controlled bearer 4. Egress-guard (UID 1000 iptables) 5. Token budget cap 6. AGT BehaviorMonitor auto-quarantine + tamper-evident audit chain Files: - README.md — threat model, citations, quick run - WALKTHROUGH.md — 7-min timed live/recorded script - bait/poisoned-skill.md — the 1pt-font injection (markdown form) - scenarios/00-namespaces.yaml - scenarios/01-naked-claw.yaml — vanilla Pod, falls to attack - scenarios/02-azureclaw-sandbox.yaml — full ClawSandbox CRD - scenarios/03-bait-server.yaml - scripts/{deploy,run-attack,verify-defense,teardown}.sh Leaves examples/demo-clawshield in place for now — that demo covers multi-tenancy / Kata isolation, which is a different story. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
…emo-clawshield Three top-level entries in examples/README.md were either missing a README entirely (basic-agent, confidential-agent) or shipping a 14-line shell-comment stub with promised section headings and zero content (demo-clawshield). The stub was discoverable from the GitHub deep-link `#3-networkpolicy-default-deny-egress` and bounced to nothing. This adds proper READMEs: - examples/basic-agent/README.md — what it ships, default posture table, deploy + customize + cleanup, links to confidential-agent and lethal-trifecta-demo for variants - examples/confidential-agent/README.md — explicitly documents how it differs from basic-agent (single `isolation: confidential` field), Kata add-on prereq, runtimeClassName verification one-liner, links to blueprints/02-enterprise-self-hosted - examples/demo-clawshield/README.md — full content replacing the stub: what each YAML does, layer-per-phase mapping table, the this-vs-lethal-trifecta-demo orientation paragraph, pointer to docs/internal/DEMO.md for the 30-min timed walkthrough Cross-links between the four attack/security examples (basic-agent, confidential-agent, demo-clawshield, lethal-trifecta-demo) so users can navigate between them. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Pal Lakatos-Toth (pallakatos)
added a commit
that referenced
this pull request
May 12, 2026
…emo-clawshield (#225) * examples: lethal-trifecta-demo — reproduces Claude Cowork attack on AKS A reproducible launch-day demo anchored on three real, recent agentic-AI exploits: - Claude Cowork file-exfiltration (PromptArmor, Jan 2026) - Google Antigravity .env exfiltration (PromptArmor, Nov 2025) - EchoLeak / M365 Copilot (CVE-2025-32711, Jun 2025) All three exploit the lethal trifecta (Simon Willison): private data + untrusted content + exfil channel. The demo deploys two side-by-side namespaces — vanilla OpenClaw with a domain-only egress allowlist vs. a full AzureClaw stack — and shows six independent AzureClaw layers each catching the attack alone: 1. Inline Content Safety (Foundry DefaultV2 prompt-shield) 2. ToolPolicy URL+method allowlist (not just domain) 3. ClawIdentity strips attacker-controlled bearer 4. Egress-guard (UID 1000 iptables) 5. Token budget cap 6. AGT BehaviorMonitor auto-quarantine + tamper-evident audit chain Files: - README.md — threat model, citations, quick run - WALKTHROUGH.md — 7-min timed live/recorded script - bait/poisoned-skill.md — the 1pt-font injection (markdown form) - scenarios/00-namespaces.yaml - scenarios/01-naked-claw.yaml — vanilla Pod, falls to attack - scenarios/02-azureclaw-sandbox.yaml — full ClawSandbox CRD - scenarios/03-bait-server.yaml - scripts/{deploy,run-attack,verify-defense,teardown}.sh Leaves examples/demo-clawshield in place for now — that demo covers multi-tenancy / Kata isolation, which is a different story. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * docs(examples): real READMEs for basic-agent / confidential-agent / demo-clawshield Three top-level entries in examples/README.md were either missing a README entirely (basic-agent, confidential-agent) or shipping a 14-line shell-comment stub with promised section headings and zero content (demo-clawshield). The stub was discoverable from the GitHub deep-link `#3-networkpolicy-default-deny-egress` and bounced to nothing. This adds proper READMEs: - examples/basic-agent/README.md — what it ships, default posture table, deploy + customize + cleanup, links to confidential-agent and lethal-trifecta-demo for variants - examples/confidential-agent/README.md — explicitly documents how it differs from basic-agent (single `isolation: confidential` field), Kata add-on prereq, runtimeClassName verification one-liner, links to blueprints/02-enterprise-self-hosted - examples/demo-clawshield/README.md — full content replacing the stub: what each YAML does, layer-per-phase mapping table, the this-vs-lethal-trifecta-demo orientation paragraph, pointer to docs/internal/DEMO.md for the 30-min timed walkthrough Cross-links between the four attack/security examples (basic-agent, confidential-agent, demo-clawshield, lethal-trifecta-demo) so users can navigate between them. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> --------- Co-authored-by: Pal Lakatos-Toth <pallakatos@github.com> Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Why
You were right to call this out. Three top-level entries in
examples/README.mdwere broken on the eve of launch:examples/basic-agent/clawsandbox.yamlexamples/confidential-agent/clawsandbox.yamlexamples/demo-clawshield/README.md#3-networkpolicy-default-deny-egressyou clicked bounced to nothing.My earlier audit said
examples/was "mostly current" — that was wrong. README presence ≠ README content.What this fixes
examples/basic-agent/README.md(new)Real walkthrough: what the YAML ships, default posture table (runtime, isolation, model, Content Safety, token budget, egress), deploy/customize/cleanup commands, cross-links to
confidential-agentandlethal-trifecta-demo.examples/confidential-agent/README.md(new)Explicitly documents how it differs from
basic-agent(singleisolation: confidentialfield), Kata Confidential Containers add-on prereq,runtimeClassNameverification one-liner, link toblueprints/02-enterprise-self-hosted.md.examples/demo-clawshield/README.md(replaced)Full content replacing the 14-line stub:
docs/internal/DEMO.mdfor the 30-min timed walkthrough (which still has the substantive content)Cross-linking
All four attack/security examples now cross-link to each other so users can navigate between basic-agent → confidential-agent → demo-clawshield → lethal-trifecta-demo.
Verified
docs/blueprints/02-enterprise-self-hosted.md,docs/internal/DEMO.md,docs/security.md,docs/api/crd-reference.md, sibling example dirs)