AI agent search demand jumped 7.5x in a quarter. Office workers in South Korea are paying premium prices for Claude Code courses and custom agent installation. The fear: fall behind, get laid off.
DryRun Security tested Claude Code, OpenAI Codex, and Google Gemini on realistic app builds. Across 30 pull requests, 87% contained at least one vulnerability. The pattern: broken access control, missing WebSocket auth, weak JWT secrets, and unmounted rate limits.
Two critical CVEs in Anthropic's Claude Code exploited MCP configuration to achieve remote code execution and API key theft. What OpenClaw users should know about supply chain attacks on AI agents.