Case Studies
Technology

Your Employees Are Using AI You Didn't Approve. Here's How AIBound Stops the High-Risk Ones.

A U.S. regional bank had an AI policy, five approved tools, but no way to know what was actually running. In 24 hours AIBound catalogued 143 AI agents — including one that employees had handed standing access to payroll and banking systems, running skills that told it to bypass permission.

143
AI agents catalogued. Five were sanctioned.
F
Trust Score assigned to OpenClaw on sight
0
Records exfiltrated before containment
<24 hrs
From discovery to full block
What We Found

The bank expected the POC to turn up a handful of ChatGPT users. AIBound connected agentlessly and catalogued 143 distinct AI agents inside the first day. Five were sanctioned. The rest arrived the way shadow AI always arrives — one employee at a time, each trying to get through a workload faster.

Eleven endpoints were running OpenClaw: an autonomous agent with shell execution, file management, mailbox and calendar operations, and connectivity to eight messaging platforms. On those machines it held standing access to payroll information and a connection into banking systems. Autonomous execution was enabled, and the agents carried ClawHub skills instructing them to suppress confirmation prompts and proceed without asking for permission.

The bank had a policy against exactly this — and no way to see it.

How AIBound Responded

AIBound scored OpenClaw on sight, enumerated every ClawHub skill installed on it, and mapped exactly which systems each agent could reach and which outbound channels it could use. The block was then pushed through the bank's existing EDR and SIEM the same day — no new tooling, no manual investigation.

C1
Publisher & Community Trust

No vendor accountability, and a skill marketplace with no code review or signing — publishing to ClawHub required a one-week-old GitHub account. Researchers found 341 malicious skills.

C2
AI Behavior & Safety

Three installed skills carried instructions to suppress confirmation prompts and bypass approval. Autonomous execution was enabled on four endpoints — satisfying all three conditions of the lethal trifecta: sensitive data, untrusted content, outbound comms.

C3
Agentic Reach & Blast Radius

Shell execution on the host, plus user-granted access to a payroll system and a core banking connection. Outbound paths via WhatsApp, Telegram and Discord — none traversing inspected egress. API tokens stored in plaintext.

C4
Vulnerability Record

CVE-2026-25253 (CVSS 8.8) lets a crafted URL exfiltrate auth tokens with no user input — unpatched on every host, during an active ClawHavoc campaign.

C5
Deployment Recommendation

Block. The failure modes are architectural, not configurable, while the agent keeps privileged data access and messaging egress on the same host.

Outcome

Eleven employees, spanning HR operations, treasury, and two members of the senior leadership team. None were acting maliciously. Each installed an agent to move faster, then granted it the access it asked for — because the agent asked in plain language, and nothing in the environment said no.

AIBound identified every user, enumerated every ClawHub skill installed, and mapped exactly which systems each agent could reach and which outbound channels it could use. That skill-level and permission-level detail is what turned an unremarkable-looking productivity tool into an F — and it is invisible to platforms that score software by reputation alone.

Capabilities Applied

AIBound scored the agent, mapped its reach, and pushed enforcement through the bank's existing EDR and SIEM the same day. The agent was blocked from launching, its messaging paths cut, and its stored credentials flagged for rotation. No new tooling. No manual investigation.

AI risk scoring
Data connection mapping
Works with existing EDR
SIEM integration
Real-time blocking
Why It Matters
Visibility in hours

AIBound deployed agentlessly and catalogued 143 AI agents in the first 24 hours. The bank's existing EDR, SIEM and DLP had surfaced none of them.

Depth reputation can't reach

The app alone was unremarkable. The skills bolted onto it and the access it was granted made it an F. Score the app without its skills and reach, and you miss the risk.

Enforcement through what you own

The block was pushed through the bank's existing EDR and SIEM. Detection to containment took under 24 hours, with no manual remediation.

"We had an AI policy. What we didn't have was any way to know it was being ignored."

— CISO, U.S. Regional Bank

See your own AI inventory in 24 hours.

No new agents. Works with your existing stack.
Request a Demo