What it is
Endor Labs describes an AI-SAST workflow that traces data across files and components, reasons about guards and reachability, and builds proof-of-concept evidence for human-reviewed disclosure.
What is verified
The initial no-CVE entry is OpenClaw’s Image Tool SSRF, published as GHSA-56f2-hvwg-5743 and fixed in OpenClaw 2026.2.2. Five other reports from the same six-finding research stream (three CVEs and two GHSA-only advisories) remain in the historical backfill queue.