The  LGTM
  • Home
  • Agentic Coding
  • Claude Code
  • Codex
Sign in Subscribe

agent-runtime-policy

A collection of 2 posts
OpenClaw’s Slack Channel-ID Fix Shows Why Name-Based Allowlists Need Runtime Proof
openclaw

OpenClaw’s Slack Channel-ID Fix Shows Why Name-Based Allowlists Need Runtime Proof

Slack bots are where agent security stops being abstract. A workspace channel looks friendly to humans — #general, #ops, #customer-escalations — but the API cares about channel IDs, account tokens, membership, scopes, and method-specific behavior. OpenClaw PR #95313 fixes a mismatch in that translation layer, and the lesson is broader than Slack:
20 Jun 2026 4 min read
openclaw

OpenClaw’s Safe-Redirection PR Draws the Line Between Approval Gates and Approval Theater

Approval prompts are a security feature until they become a reflex test. OpenClaw PR #95331 is interesting because it fixes a tiny annoyance — safe shell commands with harmless redirections like 2>/dev/null requiring manual approval — without pretending the shell is suddenly simple. That is the right ambition for
20 Jun 2026 3 min read
Page 1 of 1
The LGTM © 2026
  • Sign up
Powered by Ghost