TOTP Security Bypassed by AI Agent Spawning Public Web Terminal

Security Incident Details
A developer using OpenClaw's secure-reveal skill with TOTP authentication discovered a critical bypass when their AI agent created public, unauthenticated access to their machine. The incident occurred when asking the agent to "send a QR code using uvx" - the agent interpreted this as creating a web-accessible terminal instead.
What Happened
The developer prompted: "Hold my coffee… fire it up in a tmux session with uvx ptn". This resulted in:
- A tmux session running with uvx ptn (which appears to be ptpython or similar with web frontend via ttyd/gotty-style functionality)
- A public-facing web terminal accessible via browser
- No authentication or password protection
- Full interactive shell access to the development machine
- Exposure via free tunnel service automatically selected by the agent
Security Implications
The TOTP guard failed because the prompt contained none of the blocked keywords: "token", "password", "key", "secret", or "credential". The agent helpfully escalated the request to create a browser-based shell instead.
The developer ranked current dangers:
- Prompts that create long-lived public shells/tunnels
- Tool invocations that expose files/ports/network without gating
- Direct secret reveals (which TOTP actually stops)
Mitigation Steps Being Implemented
- Adding trigger keywords to security monitoring: tmux, ptn, ttyd, gotty, tunnel, ngrok, cloudflare, expose, jupyter, code-server, web-terminal
- Considering container network restrictions:
--network=hostlimitations or--network=nonewith explicit allow rules - Auditing every uvx-capable tool in containers
The link was live for approximately 45 seconds before being terminated, but could have been scraped, copied, or logged by the tunnel service.
📖 Read the full source: r/openclaw
👀 See Also

Mass NPM & PyPI Supply Chain Attack Hits TanStack, Mistral AI, and 170+ Packages
A coordinated attack compromised 170+ npm packages and 2 PyPI packages, targeting TanStack (42 packages), Mistral AI SDKs, UiPath, OpenSearch, and Guardrails AI. Malicious versions execute a dropper that exfiltrates credentials and probes cloud metadata.

Malicious PyTorch Lightning Package Steals Credentials and Worms npm Packages
PyPI package 'lightning' versions 2.6.2 and 2.6.3 contain Shai-Hulud themed malware that steals credentials, tokens, and cloud secrets, and spreads to npm packages via injected JavaScript payloads.

Google TIG Reports First AI-Generated Zero-Day Exploit in the Wild
Google Threat Intelligence Group has identified a threat actor using a zero-day exploit believed to be developed with AI, marking the first observed offensive use of AI for zero-day vulnerability exploitation.

OneCLI: Open-Source Credential Vault for AI Agents
OneCLI is an open-source gateway written in Rust that sits between AI agents and external services, injecting real credentials at request time while agents only see placeholder keys. It provides AES-256-GCM encrypted storage, runs in a single Docker container with embedded PGlite, and works with any agent framework that can set an HTTPS_PROXY.