Tuesday, 8 Sep 2026
  • Contact
  • Privacy Policy
  • Terms & Conditions
  • DMCA
logo logo
  • World
  • Politics
  • Crime
  • Economy
  • Tech & Science
  • Sports
  • Entertainment
  • More
    • Education
    • Celebrities
    • Culture and Arts
    • Environment
    • Health and Wellness
    • Lifestyle
  • 🔥
  • Trump
  • House
  • White
  • ScienceAlert
  • VIDEO
  • man
  • Trumps
  • Season
  • star
  • Years
Font ResizerAa
American FocusAmerican Focus
Search
  • World
  • Politics
  • Crime
  • Economy
  • Tech & Science
  • Sports
  • Entertainment
  • More
    • Education
    • Celebrities
    • Culture and Arts
    • Environment
    • Health and Wellness
    • Lifestyle
Follow US
© 2024 americanfocus.online – All Rights Reserved.
Tech and Science

NanoClaw and JFrog launch 'immune system' to block AI agents from downloading malicious code

Last updated: June 12, 2026 4:45 pm
Share
NanoClaw and JFrog launch 'immune system' to block AI agents from downloading malicious code
SHARE

Contents
The risks associated with personal autonomous AI agentsStrategies of NanoCo and JFrog to prevent malicious code executionLicensing and accessibility

The developers behind the popular, enterprise-friendly open source OpenClaw variant, NanoClaw, are collaborating with software supply chain management leader JFrog to introduce a new joint security integration. This initiative aims to safeguard NanoClaw’s autonomous agents from malicious code injections.

“These agents are doing things that you cannot necessarily control, and you cannot necessarily train,” stated Gal Marder, Chief Strategy Officer at JFrog, in an exclusive interview with VentureBeat.

Available immediately, this partnership connects NanoClaw agents directly to JFrog’s vetted software registries, ensuring AI assistants only access scanned and secure dependencies.

This launch addresses a significant and growing concern in technology: autonomous agents often install packages in the background to enhance their capabilities, frequently without the knowledge or oversight of their human operators.

“The people who are operating the agents are not necessarily developers, and they are not even aware of the implications,” said Gavriel Cohen, the creator of NanoClaw and CEO and co-founder of its new commercial services startup, NanoCo AI.

To protect the broader ecosystem, the partners are working to make this integration available completely free for the open-source community, while enterprise organizations can easily direct their agents through their existing, commercially licensed JFrog environments.

This new technical capability follows NanoCo’s initiatives to implement permissions dialogs through a partnership with Vercel and a new collaboration with Docker to enable NanoClaw agents to operate more securely, isolated within Docker virtual containers.

The risks associated with personal autonomous AI agents

When interacting with an autonomous system like NanoCo’s NanoClaw, users communicate at a high level of abstraction.

A user might simply send an audio file or a voice note, prompting the agent to independently figure out how to process it.

As Cohen explained, the agent thinks, “oh, I can’t understand voice notes, so let me go and grab a package and download something and install it and set it up and run it.”

This dynamic self-improvement makes AI agents incredibly powerful, but it also leaves them vulnerable to software supply chain attacks.

Malicious actors are increasingly corrupting open-source registries with harmful packages. Because agents autonomously fetch what they need, they bypass human scrutiny.

The operators, who may not even be developers, are largely unaware of the security implications unfolding behind the scenes.

Strategies of NanoCo and JFrog to prevent malicious code execution

The integration between NanoCo and JFrog functions as an automated defense mechanism for these AI environments.

Under the hood, NanoClaw agents are now configured to route their requests for software packages, CLI tools, and Model Context Protocol (MCP) servers exclusively through JFrog’s registries.

If an agent tries to download a compromised library—such as a vulnerable version of the popular Axios package—the JFrog registry intercepts the request.

It blocks the installation, returning a security policy error to the agent, indicating that the request was “rejected by JFrog’s registry with a 403 security policy”.

Importantly, the system doesn’t stop at blocking the threat; it creates a dynamic correction loop. The agent is informed of the vulnerability and guided to automatically find and install an approved, non-malicious version of the requested package instead.

For large organizations, this integration resolves a major compliance challenge. Marder notes that as enterprises adopt autonomous agents, they require complete visibility.

Organizations need “a system of record, we need somewhere to track what agents that’s running by whom and consuming what packages and using what skills and using what MCPs,” he told VentureBeat.

Beyond visibility, the JFrog integration provides a foundational “trust layer” and strict governance over what these automated systems are allowed to access.

Licensing and accessibility

In the realm of software distribution, licensing and access parameters dictate adoption. The NanoCo and JFrog partnership employs a dual-track strategy to serve both individual open-source developers and highly regulated enterprises.

For the open-source community, the integration is completely free. JFrog is offering open-source NanoClaw users complimentary access to secure, vetted sources of artifacts, tools, and skills.

This enables individual developers to run autonomous agents locally without being overwhelmed by manual approval requests for every dependency. Additionally, as community members create and share new “skills” for the agents, these contributions are uploaded to the registry, scanned for malicious code, and cleared before others can use them.

This infrastructure directly neutralizes the threat of corrupted community repositories.

For enterprise deployments, the architecture integrates seamlessly into an organization’s existing commercial environment. Instead of using the public open-source registry, corporate users direct their NanoClaw agents to their own internal JFrog registries.

This ensures that all agent activity complies with the company’s specific commercial licenses, internal security policies, visibility needs, and governance standards.

As AI increasingly blurs the line between human intent and machine execution, the infrastructure securing that execution must evolve. This partnership recognizes a fundamental reality: you cannot train an AI to perfectly recognize every zero-day vulnerability; instead, you must build an environment where the agent simply cannot reach the vulnerability in the first place.

TAGGED:039immuneagentsBlockCodedownloadingJFroglaunchMaliciousNanoClawsystem039
Share This Article
Twitter Email Copy Link Print
Previous Article Gen.G vs KT Rolster in LoL LCK 2026 Road to MSI Can KT Rolster upset Gen.G in League of Legends LCK 2026 Road to MSI? Series prediction and livestream
Next Article Reem Acra Resort 2027 Collection

Popular Posts

Christian Mike Johnson Looks The American People In The Eye And Lies About Taking Away Their Healthcare

PoliticusUSA remains a bastion of truth and information as mainstream media faces challenges. Support our…

July 27, 2025

Millions of Americans don’t speak English. Now they won’t be warned before weather disasters.

The Importance of Language Equity in Weather Alerts In December 2021, a devastating tornado outbreak…

April 14, 2025

Further Extending the TikTok Enforcement Delay – The White House

By the authority vested in me as President by the Constitution and the laws of…

June 19, 2025

Massive CDC layoffs include entire sections getting RIF’d

The Centers for Disease Control and Prevention (CDC) faced a significant blow on Tuesday as…

April 1, 2025

Sen. Ernst rolls out bill to study impact of government shutdown as pricetag blows past $4.4 billion

WASHINGTON — The estimated cost of the current partial government shutdown has surged to at…

October 15, 2025

You Might Also Like

Tropical Storm Dolly forms in the Atlantic
Tech and Science

Tropical Storm Dolly forms in the Atlantic

August 27, 2026
Samsung Galaxy Tab S11 8
Tech and Science

Samsung Galaxy Tab S12 Misses Launch Event – Tech Advisor

August 27, 2026
SOUTH LOS ANGELES, CA - JULY 01:ATF investigators survey damage on Thursday, July 1, 2021 after an LAPD Bomb Squad truck exploded with illegal fireworks in South Los Angeles. The truck failed to handle a planned detonation of seized explosives the night before leaving 17 people injured and damage in the neighborhood. (Photo by Sarah Reingewirtz/MediaNews Group/Los Angeles Daily News via Getty Images)
Tech and Science

ATF declares ‘major incident’ as ransomware gang claims hack

August 27, 2026
The fix for the AI agent that hijacked a company's DNS: it can propose the change, but it can't approve it
Tech and Science

The fix for the AI agent that hijacked a company's DNS: it can propose the change, but it can't approve it

August 27, 2026
logo logo
Facebook Twitter Youtube

About US


Explore global affairs, political insights, and linguistic origins. Stay informed with our comprehensive coverage of world news, politics, and Lifestyle.

Top Categories
  • Crime
  • Environment
  • Sports
  • Tech and Science
Usefull Links
  • Contact
  • Privacy Policy
  • Terms & Conditions
  • DMCA

© 2024 americanfocus.online –  All Rights Reserved.

Welcome Back!

Sign in to your account

Lost your password?