OpenA2A Blog

Insights, updates, and best practices for AI agent security and identity management

#secretless-ai#credentials#ai-coding-tools

Secretless AI: We Solved Credential Protection for AI Coding Tools

Every AI coding tool on the market reads your credentials. No tool existed to stop it. Secretless AI is the first purpose-built solution: five encrypted backends (1Password, OS Keychain, HashiCorp Vault, GCP Secret Manager, local AES-256), runtime injection, and context-window blocking. Open source.

Abdel Fane
March 12, 2026
Read More
#browserguard#chrome-extension#ai-agents

AI Browser Guard Is Now on the Chrome Web Store

AI Browser Guard is now available on the Chrome Web Store. Detect Playwright, Puppeteer, Selenium, Computer Use, and Operator in your browser. Delegation rules, emergency kill switch, session timeline. Zero network requests, fully local processing.

OpenA2A Team
March 11, 2026
Read More
#shadow-ai#agent-discovery#mcp-servers

Shadow AI Discovery: Detect Unmanaged AI Agents and MCP Servers

Shadow AI is the use of AI agents and MCP servers without organizational visibility. opena2a detect scans for running agents, discovers MCP configs, and reports governance gaps. One command to answer: what is running, and is it governed?

OpenA2A Team
March 7, 2026
Read More
#shield#defense-in-depth#runtime-security

From Scanning to Shielding: Defense-in-Depth for AI Agents

Scanning finds vulnerabilities. Shielding prevents exploitation. OpenA2A Shield combines credential protection, configuration integrity monitoring, runtime detection, and security posture scoring into a unified layer for AI projects.

OpenA2A Team
March 4, 2026
Read More
#credentials#ai-coding-tools#security

Your AI Coding Tools Are Leaking Your API Keys

AI coding assistants read your .env files, terminal history, and MCP server configs. Every API key in your project is one autocomplete away from a cloud log. Here is how to protect credentials without breaking your workflow.

OpenA2A Team
March 1, 2026
Read More
#oasb#benchmark#ai-agents

OASB: Why AI Agents Need CIS-Style Security Benchmarks

AI agents are deploying faster than security teams can assess them. OASB brings the CIS Benchmark model to agentic AI -- 46 controls, 10 categories, 3 maturity levels. Machine-readable, automatable, and open source.

OpenA2A Team
February 21, 2026
Read More
#arp#runtime-security#ai-agents

Introducing ARP: Runtime Security for AI Agents

ARP (Agent Runtime Protection) monitors OS-level activity and AI-layer traffic with 20 built-in threat patterns. Process, network, filesystem monitoring plus prompt injection, MCP exploitation, and A2A attack detection. EDR for AI agents.

OpenA2A Team
February 19, 2026
Read More
#openclaw#security#open-source

Securing OpenClaw: 6 Security Fixes Landed in Main

We contributed 6 security fixes to OpenClaw (205K+ stars). 4 PRs merged directly, 2 adopted by maintainers. Fixes cover credential redaction, code safety scanning, path traversal, file permissions, timing side-channels, and npm lifecycle attacks.

OpenA2A Team
February 17, 2026
Read More
#agent-identity#cryptography#ai-agents

How Do You Give an AI Agent a Verifiable, Auditable, Enforceable Identity?

AI agents are making decisions, calling APIs, and accessing sensitive data autonomously. But most have no real identity — just shared API keys and bearer tokens. Here's how to give every agent a cryptographic identity that's verifiable, auditable, and enforceable at runtime.

Abdel Fane
February 11, 2026
Read More
#openclaw#security#supply-chain

OpenClaw Merges Built-In Skill Security Scanner

PR #9806 merged 1,721 lines of code into OpenClaw (205K+ GitHub stars), adding a built-in skill security scanner that detects malicious patterns across 6 check categories before skills can execute. The scanner runs automatically at install and update time.

OpenA2A Team
February 6, 2026
Read More
#nhi#ai-agents#governance

Why Your NHI Strategy Doesn't Cover AI Agents

Traditional NHI platforms manage service accounts and API keys. But AI agents represent a fundamentally different class of non-human identity that requires purpose-built governance. Here's the gap in your NHI strategy.

Abdel Fane
February 2, 2026
Read More

Stay Updated on AI Agent Security

Subscribe to our newsletter for weekly insights, vulnerability alerts, and best practices

Ready to Secure Your AI Agents?

Get started with AIM and protect your AI infrastructure with just one line of code