Digest #226: OpenClaw agents with credentials to everything, Cloudflare OS, Claude as a Postgres engine and €1.5M off a multi-cloud bill
A single semicolon that gave remote code execution on github.com, poisoning an LLM through S3 Vectors metadata, and the reason COUNT(DISTINCT) quietly kills parallel queries in Postgres.
Permiso’s teardown of the OpenClaw ecosystem is the one to read first: agents installing skills from an unvetted marketplace while holding live credentials to email, Slack and everything else they touch. Cloudflare shipped its own answer to that problem this week with Cloudflare OS, an open platform that puts guardrails around what an agent can actually reach. And if you want proof that we are all still improvising, someone wired Claude up as a Postgres query engine and it returned real rows.
If you have feedback to share or are interested in sponsoring this newsletter, feel free to reach out via LinkedIn or simply reply to this email.
Newsworthy stories
Tutorials of the week
Accelerate CloudFormation development with the IaC MCP Server
Improve your monthly cloud variance analysis with a weekly FinOps checkpoint
Centralize cross-account Amazon ECS telemetry with an ADOT gateway
A security analysis of Amazon S3 Vectors and its use in LLM retrieval pipelines
Videos of the week
Projects of the week
pgGraph runs graph traversals and shortest-path queries directly on your existing Postgres tables.
nono sandboxes any AI agent behind least-privilege isolation with no setup.
glab-tui browses GitLab and GitHub issues, merge requests, pipelines, and runners without leaving your terminal.
Suzaku hunts threats in AWS CloudTrail logs by applying Sigma detection rules to your API call history.
Svix handles webhook delivery, retries, and signing so you never have to build that layer yourself.
Starboard keeps a terminal permanently docked beside the macOS Dock instead of hidden behind a hotkey.




