the whole clawdbot situation makes me realize people don’t take security seriously with AI. assuming you will get prompt injected is step 1
then you need defense in depth: granular short lived credentials, outgoing request auditing and policies (static + ML), domain allow lists, x.com/rahulsood/stat…