OpenClaw input flaws let hidden contacts and phishing emails trigger code execution and data leaks, exposing agent trust ...