A GitHub Issue Title Compromised 4,000 Developer Machines

A prompt injection in a GitHub issue triggered a chain reaction that ended with 4,000 developers getting OpenClaw installed without consent. The attack composes well-understood vulnerabilities into something new: one AI tool bootstrapping another.

@Migueldeicaza Atm I can see some requests on /mcp and /sse HTTP paths here in my logs. Does this have something to do with this issue?