TL;DR: OpenClaw rapidly reached 150,000 GitHub stars and 300,000 to 400,000 users in under two weeks, while researchers found 341 malicious skills, CVE-2026-25253 with CVSS 8.8, and 42,665 exposed instances, according to EnforceAuth. The real failure is not access control alone but the assumption that authenticated agents can be safely governed after they begin acting independently.
Editorial analysis by NHI Mgmt Group, based on content published by EnforceAuth: “Closing the Authorization Gap: How EnforceAuth Solves the Security Crisis in Autonomous AI Agents”.
By the numbers:
- Researchers discovered 341 malicious skills designed to steal credentials.
- CVE-2026-25253, rated CVSS 8.8, enabled one-click full gateway compromise.
Key questions
Q: What breaks when IAM controls are applied to autonomous agents without runtime governance?
A: IAM controls break when they assume access can be reviewed after the fact.
Q: Why do AI agents create a different authorisation problem from ordinary automation?
A: Ordinary automation follows predefined rules, so the access path is known before execution starts.
Q: What are the signs that autonomous AI agent controls are not working in practice?
A: A strong warning sign is when teams cannot explain which actions an agent took, what data it touched, or whether those actions stayed within the approved test scope.
Practitioner guidance
- Define runtime authorization boundaries for agent actions Map which reads, writes, tool calls, and external communications require per-action approval for autonomous agents, then enforce those boundaries before execution rather than after login.
- Inventory persistent agent memory and stored context Identify files, databases, and session artifacts that carry agent state across runs, and classify them as governed inputs that can influence future behaviour.
- Constrain third-party skills and external instructions Approve only trusted skill sources, block unaudited extensions, and treat public content channels as untrusted until policy evaluation passes.
Bottom line: OpenClaw demonstrates that autonomous agent governance fails when identity controls stop at authentication and never reach runtime decisions.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Authorization can no longer be treated as a post-login question: autonomous agents break the IAM assumption that authentication is the main security event. Once an agent can choose tools, sequence actions, and persist memory without human approval, the real control point shifts to runtime decisioning. The implication is that identity programmes must stop treating login success as a proxy for safe behaviour.
A few things that frame the scale:
- 28% of secrets incidents now originate outside code repositories, in Slack, Jira, and Confluence, and are 13% more likely to be categorised as critical than code-based leaks, according to the State of Secrets Sprawl 2026.
A question worth separating out:
Q: How should teams respond when AI agents can reach backend systems?
A: Treat each connector as a governed delegation path with explicit ownership, scoped permissions, and logging. If an agent can move data across systems, it needs controls closer to PAM and NHI governance than to ordinary application usage oversight.
👉 Read our full editorial: OpenClaw exposes why autonomous agent governance is breaking IAM