OpenClaw is Cooked: 433 CVEs Patched by Agents That Can’t Fix What’s Broken

118 · Flying Penguin Blog · May 7, 2026, 10:51 a.m.
Summary
This blog post discusses a serious issue with the GitHub repository ClawCode, highlighting an integrity breach indicated by its suspicious activity and inflated star count despite lacking substantial contributions. The author raises concerns about the effectiveness of agents patching vulnerabilities (CVEs) in such repositories.