CNCERT warns OpenClaw AI agent has weak defaults enabling prompt injection and data leaks, prompting China to restrict use on government systems.
The technique exploits Unicode Private Use Area characters, which render as zero-width whitespace in virtually every code editor and terminal.