Skip to content

docs(examples): real READMEs for basic-agent / confidential-agent / demo-clawshield - #225

Merged
Pal Lakatos-Toth (pallakatos) merged 2 commits into
devfrom
docs/examples-readme-fixes
May 5, 2026
Merged

Pal Lakatos-Toth (pallakatos) merged 2 commits into
devfrom
docs/examples-readme-fixes

Conversation

@pallakatos

Copy link
Copy Markdown
Collaborator

Why

You were right to call this out. Three top-level entries in examples/README.md were broken on the eve of launch:

Path What it shipped
examples/basic-agent/ No README — just clawsandbox.yaml
examples/confidential-agent/ No README — just clawsandbox.yaml
examples/demo-clawshield/README.md 14-line shell-comment stub with promised section headings and zero actual content. The deep-link #3-networkpolicy-default-deny-egress you clicked bounced to nothing.

My earlier audit said examples/ was "mostly current" — that was wrong. README presence ≠ README content.

What this fixes

examples/basic-agent/README.md (new)

Real walkthrough: what the YAML ships, default posture table (runtime, isolation, model, Content Safety, token budget, egress), deploy/customize/cleanup commands, cross-links to confidential-agent and lethal-trifecta-demo.

examples/confidential-agent/README.md (new)

Explicitly documents how it differs from basic-agent (single isolation: confidential field), Kata Confidential Containers add-on prereq, runtimeClassName verification one-liner, link to blueprints/02-enterprise-self-hosted.md.

examples/demo-clawshield/README.md (replaced)

Full content replacing the 14-line stub:

  • What each YAML in the directory does
  • Phase-to-layer mapping table (which AzureClaw layer catches each attack phase)
  • This-vs-lethal-trifecta-demo orientation paragraph (multi-tenant isolation story vs. inference data-path story — they're complementary)
  • Pointer to docs/internal/DEMO.md for the 30-min timed walkthrough (which still has the substantive content)

Cross-linking

All four attack/security examples now cross-link to each other so users can navigate between basic-agent → confidential-agent → demo-clawshield → lethal-trifecta-demo.

Verified

  • All cross-link targets exist (docs/blueprints/02-enterprise-self-hosted.md, docs/internal/DEMO.md, docs/security.md, docs/api/crd-reference.md, sibling example dirs)
  • Markdown renders cleanly (no orphan headings)

Pal Lakatos-Toth and others added 2 commits May 5, 2026 13:09
A reproducible launch-day demo anchored on three real, recent
agentic-AI exploits:

- Claude Cowork file-exfiltration (PromptArmor, Jan 2026)
- Google Antigravity .env exfiltration (PromptArmor, Nov 2025)
- EchoLeak / M365 Copilot (CVE-2025-32711, Jun 2025)

All three exploit the lethal trifecta (Simon Willison): private data +
untrusted content + exfil channel. The demo deploys two side-by-side
namespaces — vanilla OpenClaw with a domain-only egress allowlist vs.
a full AzureClaw stack — and shows six independent AzureClaw layers
each catching the attack alone:

  1. Inline Content Safety (Foundry DefaultV2 prompt-shield)
  2. ToolPolicy URL+method allowlist (not just domain)
  3. ClawIdentity strips attacker-controlled bearer
  4. Egress-guard (UID 1000 iptables)
  5. Token budget cap
  6. AGT BehaviorMonitor auto-quarantine
  + tamper-evident audit chain

Files:
- README.md           — threat model, citations, quick run
- WALKTHROUGH.md      — 7-min timed live/recorded script
- bait/poisoned-skill.md         — the 1pt-font injection (markdown form)
- scenarios/00-namespaces.yaml
- scenarios/01-naked-claw.yaml   — vanilla Pod, falls to attack
- scenarios/02-azureclaw-sandbox.yaml — full ClawSandbox CRD
- scenarios/03-bait-server.yaml
- scripts/{deploy,run-attack,verify-defense,teardown}.sh

Leaves examples/demo-clawshield in place for now — that demo covers
multi-tenancy / Kata isolation, which is a different story.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
…emo-clawshield

Three top-level entries in examples/README.md were either missing a
README entirely (basic-agent, confidential-agent) or shipping a 14-line
shell-comment stub with promised section headings and zero content
(demo-clawshield). The stub was discoverable from the GitHub deep-link
`#3-networkpolicy-default-deny-egress` and bounced to nothing.

This adds proper READMEs:

- examples/basic-agent/README.md — what it ships, default posture table,
  deploy + customize + cleanup, links to confidential-agent and
  lethal-trifecta-demo for variants

- examples/confidential-agent/README.md — explicitly documents how it
  differs from basic-agent (single `isolation: confidential` field),
  Kata add-on prereq, runtimeClassName verification one-liner, links to
  blueprints/02-enterprise-self-hosted

- examples/demo-clawshield/README.md — full content replacing the stub:
  what each YAML does, layer-per-phase mapping table, the
  this-vs-lethal-trifecta-demo orientation paragraph, pointer to
  docs/internal/DEMO.md for the 30-min timed walkthrough

Cross-links between the four attack/security examples (basic-agent,
confidential-agent, demo-clawshield, lethal-trifecta-demo) so users
can navigate between them.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
@pallakatos
Pal Lakatos-Toth (pallakatos) merged commit 5599c2c into dev May 5, 2026
21 checks passed
Pal Lakatos-Toth (pallakatos) added a commit that referenced this pull request May 12, 2026
…emo-clawshield (#225)

* examples: lethal-trifecta-demo — reproduces Claude Cowork attack on AKS

A reproducible launch-day demo anchored on three real, recent
agentic-AI exploits:

- Claude Cowork file-exfiltration (PromptArmor, Jan 2026)
- Google Antigravity .env exfiltration (PromptArmor, Nov 2025)
- EchoLeak / M365 Copilot (CVE-2025-32711, Jun 2025)

All three exploit the lethal trifecta (Simon Willison): private data +
untrusted content + exfil channel. The demo deploys two side-by-side
namespaces — vanilla OpenClaw with a domain-only egress allowlist vs.
a full AzureClaw stack — and shows six independent AzureClaw layers
each catching the attack alone:

  1. Inline Content Safety (Foundry DefaultV2 prompt-shield)
  2. ToolPolicy URL+method allowlist (not just domain)
  3. ClawIdentity strips attacker-controlled bearer
  4. Egress-guard (UID 1000 iptables)
  5. Token budget cap
  6. AGT BehaviorMonitor auto-quarantine
  + tamper-evident audit chain

Files:
- README.md           — threat model, citations, quick run
- WALKTHROUGH.md      — 7-min timed live/recorded script
- bait/poisoned-skill.md         — the 1pt-font injection (markdown form)
- scenarios/00-namespaces.yaml
- scenarios/01-naked-claw.yaml   — vanilla Pod, falls to attack
- scenarios/02-azureclaw-sandbox.yaml — full ClawSandbox CRD
- scenarios/03-bait-server.yaml
- scripts/{deploy,run-attack,verify-defense,teardown}.sh

Leaves examples/demo-clawshield in place for now — that demo covers
multi-tenancy / Kata isolation, which is a different story.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* docs(examples): real READMEs for basic-agent / confidential-agent / demo-clawshield

Three top-level entries in examples/README.md were either missing a
README entirely (basic-agent, confidential-agent) or shipping a 14-line
shell-comment stub with promised section headings and zero content
(demo-clawshield). The stub was discoverable from the GitHub deep-link
`#3-networkpolicy-default-deny-egress` and bounced to nothing.

This adds proper READMEs:

- examples/basic-agent/README.md — what it ships, default posture table,
  deploy + customize + cleanup, links to confidential-agent and
  lethal-trifecta-demo for variants

- examples/confidential-agent/README.md — explicitly documents how it
  differs from basic-agent (single `isolation: confidential` field),
  Kata add-on prereq, runtimeClassName verification one-liner, links to
  blueprints/02-enterprise-self-hosted

- examples/demo-clawshield/README.md — full content replacing the stub:
  what each YAML does, layer-per-phase mapping table, the
  this-vs-lethal-trifecta-demo orientation paragraph, pointer to
  docs/internal/DEMO.md for the 30-min timed walkthrough

Cross-links between the four attack/security examples (basic-agent,
confidential-agent, demo-clawshield, lethal-trifecta-demo) so users
can navigate between them.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

---------

Co-authored-by: Pal Lakatos-Toth <pallakatos@github.com>
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
@pallakatos
Pal Lakatos-Toth (pallakatos) deleted the docs/examples-readme-fixes branch June 1, 2026 14:39
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant