• bitcoinBitcoin(BTC)$65,634.00-0.30%
  • ethereumEthereum(ETH)$1,925.800.20%
  • tetherTether(USDT)$1.000.00%
  • binancecoinBNB(BNB)$569.66-0.10%
  • usd-coinUSDC(USDC)$1.000.00%
  • rippleXRP(XRP)$1.130.00%
  • solanaSolana(SOL)$77.730.20%
  • tronTRON(TRX)$0.328185-0.40%
  • Figure HelocFigure Heloc(FIGR_HELOC)$1.00-0.30%
  • whitebitWhiteBIT Coin(WBT)$57.350.00%
  • HyperliquidHyperliquid(HYPE)$59.090.20%
  • dogecoinDogecoin(DOGE)$0.072321-0.10%
  • RainRain(RAIN)$0.014263-2.00%
  • USDSUSDS(USDS)$1.000.00%
  • leo-tokenLEO Token(LEO)$9.730.10%
  • zcashZcash(ZEC)$514.60-0.30%
  • moneroMonero(XMR)$352.930.50%
  • cardanoCardano(ADA)$0.1744870.70%
  • chainlinkChainlink(LINK)$8.610.10%
  • stellarStellar(XLM)$0.184810-2.50%
  • CantonCanton(CC)$0.120293-3.40%
  • daiDai(DAI)$1.000.00%
  • bitcoin-cashBitcoin Cash(BCH)$216.15-2.10%
  • USD1USD1(USD1)$1.000.00%
  • the-open-networkGram (prev. Toncoin)(GRAM)$1.511.10%
  • Ethena USDeEthena USDe(USDE)$1.000.00%
  • litecoinLitecoin(LTC)$46.770.70%
  • Global DollarGlobal Dollar(USDG)$1.000.00%
  • hedera-hashgraphHedera(HBAR)$0.0735574.30%
  • suiSui(SUI)$0.771.30%
  • Circle USYCCircle USYC(USYC)$1.13-0.10%
  • avalanche-2Avalanche(AVAX)$6.591.30%
  • crypto-com-chainCronos(CRO)$0.0585471.60%
  • paypal-usdPayPal USD(PYUSD)$1.000.00%
  • BlackRock USD Institutional Digital Liquidity FundBlackRock USD Institutional Digital Liquidity Fund(BUIDL)$1.000.00%
  • tether-goldTether Gold(XAUT)$4,085.12-0.50%
  • shiba-inuShiba Inu(SHIB)$0.000004-0.20%
  • nearNEAR Protocol(NEAR)$1.880.50%
  • uniswapUniswap(UNI)$3.833.00%
  • Ondo US Dollar YieldOndo US Dollar Yield(USDY)$1.140.00%
  • World Liberty FinancialWorld Liberty Financial(WLFI)$0.06311513.30%
  • OndoOndo(ONDO)$0.4030920.00%
  • BittensorBittensor(TAO)$195.52-0.70%
  • pax-goldPAX Gold(PAXG)$4,083.72-0.50%
  • okbOKB(OKB)$84.503.30%
  • AsterAster(ASTER)$0.62-0.10%
  • HTX DAOHTX DAO(HTX)$0.0000020.40%
  • Ripple USDRipple USD(RLUSD)$1.000.00%
  • usddUSDD(USDD)$1.000.00%
  • MemeCoreMemeCore(M)$1.15-1.70%
TradePoint.io
  • Main
  • AI & Technology
  • Stock Charts
  • Market & News
  • Business
  • Finance Tips
  • Trade Tube
  • Blog
  • Shop
No Result
View All Result
TradePoint.io
No Result
View All Result

NanoClaw and JFrog launch ‘immune system’ to block AI agents from downloading malicious code

June 12, 2026
in AI & Technology
Reading Time: 4 mins read
A A
NanoClaw and JFrog launch ‘immune system’ to block AI agents from downloading malicious code
ShareShareShareShareShare

The creators of the hit, enterprise-friendly, open source OpenClaw variant NanoClaw are partnering with software supply chain management leader JFrog have to launch a new, joint security integration they say will protect NanoClaw autonomous agents from malicious code injection.

YOU MAY ALSO LIKE

Best Open Speech Recognition (ASR) Models in 2026: WER, Languages, Latency, and License Compared

A SpaceX Falcon 9 Rocket Is Expected To Crash Into The Moon This August

“These agents are doing things that you cannot necessarily control, and you cannot necessarily train,” said Gal Marder, Chief Strategy Officer at JFrog, in an exclusive interview with VentureBeat.

Available immediately, the partnership hardwires NanoClaw agents directly to JFrog’s vetted software registries, ensuring that AI assistants can only pull scanned, safe dependencies.

The release addresses a rapidly growing blind spot in tech: autonomous agents frequently install packages in the background to extend their capabilities, often without their human operators’ knowledge or oversight.

“The people who are operating the agents are not necessarily developers, and they are not even aware of the implications,” explained Gavriel Cohen, creator of NanoClaw and CEO and co-founder of its new commercial services startup, NanoCo AI.

To secure the broader ecosystem, the integration is available completely free of charge for the open-source community, while enterprise organizations can seamlessly route their agents through their existing, commercially licensed JFrog environments.

The new technical capability enabled by this partnership follows NanoCo’s moves to add permissions dialogs across the apps in which it’s available via a partnership with Vercel, and a new partnership with Docker to allow NanoClaw agents to run more securely, isolated from other software environments directly inside Docker virtual containers.

The risk of current, personal autonomous AI agents

When an operator interacts with an autonomous system like NanoCo’s NanoClaw, they communicate at a high level of abstraction.

A user might simply send an audio file or a voice note, prompting the agent to independently figure out how to process it.

As Cohen explained, the agent thinks, “oh, I can’t understand voice notes, so let me go and grab a package and download something and install it and set it up and run it”.

This dynamic self-improvement makes AI agents incredibly powerful, but it also renders them highly susceptible to software supply chain attacks.

Bad actors are increasingly poisoning open-source registries with malicious packages. Because agents act autonomously to fetch what they need, they bypass human scrutiny.

The operators, who may not even be developers, are largely unaware of the security implications unfolding behind the scenes.

How NanoCo and JFrog are working to stop agents from running malicious code

The integration between NanoCo and JFrog acts as an automated immune system for these AI environments.

Under the hood, NanoClaw agents are now configured to route their requests for software packages, CLI tools, and Model Context Protocol (MCP) servers exclusively through JFrog’s registries.

If an agent attempts to download a compromised library—such as a vulnerable version of the popular Axios package—the JFrog registry intercepts the request.

It blocks the installation, returning a security policy error to the agent, noting that the request was “rejected by JFrog’s registry with a 403 security policy”.

Crucially, the system does not just stop at blocking the threat; it creates a dynamic correction loop. The agent is notified of the vulnerability and guided to automatically seek out and install an approved, non-malicious version of the requested package instead.

For large organizations, this integration solves a massive compliance headache. Marder notes that as enterprises adopt autonomous agents, they require absolute visibility.

Organizations need “a system of record, we need somewhere to track what agents that’s running by whom and consuming what packages and using what skills and using what MCPs,” he told VentureBeat.

Beyond visibility, the JFrog integration provides a foundational “trust layer” and strict governance over what these automated systems are permitted to access.

Licensing and accessibility

In the realm of software distribution, licensing and access parameters dictate adoption. The NanoCo and JFrog partnership utilizes a dual-track approach to serve both individual open-source developers and highly regulated enterprises.

For the open-source community, the integration is completely free. JFrog is providing open-source NanoClaw users with complimentary access to safe, vetted sources of artifacts, tools, and skills.

This allows individual developers to run autonomous agents locally without drowning in manual approval requests for every single dependency. Furthermore, as community members build and share new “skills” for the agents, these contributions are uploaded to the registry, scanned for malicious code, and cleared before anyone else can use them.

This infrastructure directly neutralizes the threat of poisoned community repositories.

For enterprise deployments, the architecture plugs seamlessly into an organization’s existing commercial environment. Rather than using the public open-source registry, corporate users point their NanoClaw agents to their own internal JFrog registries.

This ensures that all agent activity adheres to the company’s specific commercial licenses, internal security policies, visibility needs, and governance standards.

As AI continues to blur the line between human intent and machine execution, the infrastructure securing that execution must evolve. This partnership acknowledges a core reality: you cannot train an AI to perfectly recognize every zero-day vulnerability; instead, you must build an environment where the agent simply cannot reach the vulnerability in the first place.

Credit: Source link

ShareTweetSendSharePin

Related Posts

Best Open Speech Recognition (ASR) Models in 2026: WER, Languages, Latency, and License Compared
AI & Technology

Best Open Speech Recognition (ASR) Models in 2026: WER, Languages, Latency, and License Compared

July 23, 2026
A SpaceX Falcon 9 Rocket Is Expected To Crash Into The Moon This August
AI & Technology

A SpaceX Falcon 9 Rocket Is Expected To Crash Into The Moon This August

July 23, 2026
Anthropic Releases Claude Security Plugin for Claude Code in Beta: A Multi-Agent Vulnerability Scanner That Runs in Your Terminal
AI & Technology

Anthropic Releases Claude Security Plugin for Claude Code in Beta: A Multi-Agent Vulnerability Scanner That Runs in Your Terminal

July 23, 2026
Cursor Releases Cursor Router: A Request-Level Classifier Delivering Frontier Coding Quality at 30–50% Lower Cost
AI & Technology

Cursor Releases Cursor Router: A Request-Level Classifier Delivering Frontier Coding Quality at 30–50% Lower Cost

July 22, 2026
Next Post
The 0 Billion Data Center Transforming Louisiana

The $200 Billion Data Center Transforming Louisiana

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Search

No Result
View All Result
A Sigh of Relief on Inflation

A Sigh of Relief on Inflation

July 19, 2026
The Best Trick To Buying Your First AI Stock!

The Best Trick To Buying Your First AI Stock!

July 20, 2026
Man fatally shot by police officer in Madison, prompting protest in city – The Washington Post

Man fatally shot by police officer in Madison, prompting protest in city – The Washington Post

July 23, 2026

About

Learn more

Our Services

Legal

Privacy Policy

Terms of Use

Bloggers

Learn more

Article Links

Contact

Advertise

Ask us anything

©2020- TradePoint.io - All rights reserved!

Tradepoint.io, being just a publishing and technology platform, is not a registered broker-dealer or investment adviser. So we do not provide investment advice. Rather, brokerage services are provided to clients of Tradepoint.io by independent SEC-registered broker-dealers and members of FINRA/SIPC. Every form of investing carries some risk and past performance is not a guarantee of future results. “Tradepoint.io“, “Instant Investing” and “My Trading Tools” are registered trademarks of Apperbuild, LLC.

This website is operated by Apperbuild, LLC. We have no link to any brokerage firm and we do not provide investment advice. Every information and resource we provide is solely for the education of our readers. © 2020 Apperbuild, LLC. All rights reserved.

No Result
View All Result
  • Main
  • AI & Technology
  • Stock Charts
  • Market & News
  • Business
  • Finance Tips
  • Trade Tube
  • Blog
  • Shop

© 2023 - TradePoint.io - All Rights Reserved!