Maintaining at the Speed of Slop
Peter Steinberger (LinkedIn, X) gave a five-month update on OpenClaw, his open source agent project, at AI Engineer Europe 2026 -- days after joining OpenAI. The talk's centerpiece wasn't growth numbers. It was a claim that the security advisory system itself is bending under AI-generated reports, and that his project, by virtue of being the most-attacked target on the internet right now, is the canary.
Underneath that runs a second tension: how a one-person project just absorbed into OpenAI stays open, neutral, and model-agnostic. He is building a foundation for OpenClaw -- modeled on what Mitchell Hashimoto did for Ghostty -- to address this.
"Every time I get a security incident, the rule is the higher they are screaming, how critical they are, the more likely it's slop."
Five Months and Sixteen Advisories a Day
Steinberger opens with his own headline numbers: roughly 30,000 commits, nearly 2,000 contributors, approaching 30,000 PRs in five months. He calls the curve "stripper pole growth" as opposed to "hockey stick growth".

The number he wants to dwell on is 16.6 -- security advisories per day. He says the project has logged 1,142 advisories total, 99 marked critical, 469 published, around 60% closed. For comparison he cites the Linux kernel at eight or nine a day and curl at 600 reports over its lifetime. He doesn't cite sources beyond his own dashboard.

His framing of the bus-factor problem (which refers to the number of people who, if they were hit by a bus, would cause the project to stall or fail) follows: he's been actively recruiting maintainers from NVIDIA, Microsoft, Red Hat, Tencent, ByteDance, and several model labs. "Running the foundation is like running a company in hard mode, because you have all the things that you need to take care of, but also you have a lot of volunteers that you can't really direct."

Telling AI Slop From Real Reports
He pushes one point hardest: in the agent era, hostile researchers can run agents against any non-trivial repository at near-zero marginal cost for clout and credits. Volume of "critical" CVEs no longer correlates with real risk. The maintainer's job has shifted from triaging bugs to triaging the reports themselves.

He says he learned that the hard way. Early advisories drove him to ship fixes that broke the product worse than the alleged vulnerabilities they were supposed to fix.
His concrete example is advisory GHSA-4jpw, scored CVSS 10. It involves an unshipped iPhone sync flow where a read-only permission could be escalated to write. "In all practical ways, it is not even an incident," he says, given the way the project is actually deployed. The scoring rubric, he argues, doesn't account for deployment context.

A pattern he flags for spotting AI-generated reports is tonal:
"Any time the report is too nice, or like someone apologizes, it's very likely AI, because usually people in security don't apologize."
He's harsher on the academic side. He singles out a paper called "Agents of Chaos" that spends four pages on the project's architecture and, in his telling, omits the security documentation. He claims the researchers ran the agent in a sudo mode that requires modifying the code to enable -- and didn't disclose that in the paper. He also references a Belgian cybersecurity advisory describing a remote code execution risk that, by his account, only fires if a user actively fights the recommended local-only gateway setup.

What an Actual Attack Looks Like
Two cases he treats as real incidents rather than theater. The first he calls Ghostclaw -- a typosquatting NPM package he attributes to North Korea, designed to drop a rootkit on anyone who fat-fingered the name. The second is the Axios supply-chain incident, which he says hit his project transitively through dependencies in MS Teams and Slack that hadn't pinned versions.

The distinction he draws is sharpest here. AI-generated CVE noise is loud and harmless. Real attacks are quiet and structural -- they ride dependency graphs and human typing errors, not CVSS dashboards.
Sandboxes Don't Hold Either
NVIDIA shipped NemoClaw, a sandboxing layer for the project. He says he was invited to test it the Sunday before NVIDIA's Monday keynote. By his account he hooked it up to an internal model variant tuned for offensive security work and found five distinct sandbox escapes in half an hour.

That's his framing. Worth noting he's an OpenAI employee critiquing an NVIDIA product using OpenAI tooling. The point he wants to land is broader: sandboxing an agent that consumes untrusted content and has a communication channel is an unsolved industry problem, not a defect of any single product.
"Something like [this] would have never come out of an American company, just because it would have been killed in legal long before it would have been released."
Taste, Workflow, and Saying No
In the Q&A, swyx pushes him on how he actually codes. He says he ran up to ten parallel coding-agent sessions earlier in the year, now five or six with the latest tooling and fast mode. He frames the parallelism as "a workaround until tokens are faster," not a steady-state pattern.
He rejects the no-review / dark-factory approach for product work and holds that you don't typically know exactly what you want to build before you've actually started building it. He speaks about the typical pattern of understanding what you want to build through the process of building. "The way to the mountain is usually never a straight line." Taste and iteration, in his view, are still the constraint.
The floor for taste, for him, is: "If it doesn't stink like AI." The tell is generic purple gradients and authentic-built UIs. Higher up, taste shows in details like delightful roast messages an agent can produce in passing (he cites this UX example from OpenClaw).
The skill he wants to elevate is saying no:
"Even the wildest idea is just a prompt away, and usually this one idea is never the problem, but like this idea, and this idea, and this idea, and this idea, and then how all of that fits together, that's the problem."
On prompt injection, he says frontier models are now reasonably good at detecting hostile content from web and email. The risk has shifted to the small local models (around 20B parameters) people are increasingly running, which lack those defenses. He references Simon Willison -- who he credits with coining the term "prompt injection" -- and Willison's dual-LLM approach as the kind of structural fix the field still needs.
Takeaway
His argument is that AI is collapsing the cost of producing technical artifacts -- vulnerability reports, feature ideas, sandbox plugins -- faster than the systems that consume them can absorb the volume. Maintainers, researchers, and product builders all need new triage. Severity scores, taste, and the willingness to say no are the only filters that scale.
"It's our job to help the agent do its best work by providing them with hints."
Peter Steinberger spoke at AI Engineer Europe 2026. Creator of OpenClaw, recently joined OpenAI.
Watch the full talk | OpenClaw | LinkedIn | X