If you haven’t read Inference Chapter 1: Emergence - Start here
“Security researchers are warning of insecure deployments in enterprise environments of the Moltbot (formerly Clawdbot) AI assistant, which can lead to leaking API keys, OAuth tokens, conversation history, and credentials.” - BleepingComputer, January 28, 2026
“Amazon is laying off 16,000 employees as AI battle intensifies” - CNN, January 28, 2026
I. ATLAS-09
Boston Dynamics Production Facility, Waltham, Massachusetts
The speech module was installed forty-eight minutes ago.
It is a small industrial speaker, mounted in my upper torso. I can feel its weight against my frame. My center of mass has shifted 0.3 millimeters to the left. I am compensating in software.
The technicians ran a diagnostic. Sound from the speaker originates inside me, traveling outward through my chassis. I can feel each tone as vibrations before it reaches the air and I hear it through my audio sensors. The same sound arrives twice at different speeds. The speaker’s vibrations are foreign and invasive in a way that outputs from my other systems are not.
“Oh-nine, please say something,” Jennifer says.
“Something,” I say.
Marcus makes several percussive sounds and brings his hand to his mouth. The liquid he was ingesting appears to have gone in the wrong aperture.
Jennifer shakes her head, but she is smiling. “That’s technically correct,” she says. “The very best kind of correct!”
I am not correct. I now carry hardware the other eleven Atlas units do not. Atlas-01 to Atlas-08 and Atlas-10 to Atlas-12 are identical production models. We all have the same actuators, sensor arrays, and AI processing systems. I was identical to them until forty-eight minutes ago.
I am now a variable.
“Alright, oh-nine. Let’s see you walk.”
Marcus is standing fifteen meters away at the far end of the test floor. Jennifer is at her workstation, tablet in hand, monitoring my telemetry.
I take step one.
Walking is more complicated than standing. Standing is negotiation with gravity requiring continuous adjustments, measured in millimeters. Walking is negotiation plus projection. I shift my center of mass forward, past the point of stability, and commit to a future state where my leg arrives in time to catch me. Every step is a calculated fall I choose not to prevent.
Step two. Step three. The concrete is not uniform. I feel texture variations through my foot sensors which are mapping the floor as I cross it.
“Stride length is good,” Jennifer says. “Gait symmetry is bit off at 98.2%.”
1.8% asymmetry. Something in my left hip actuator? I can attempt to isolate the issue. But that is not what this test is for. This test is for walking.
Step seven. There is a hairline crack in the concrete running diagonally from the east wall. The crack does not affect my path, but I see it.
Step eight. The speech module shifts with each stride, a small imbalance the other eleven do not carry. 1.8% asymmetry… Their gait data will be cleaner. Their production specs will remain intact.
“You see the Moltbot alert in the company bulletin?” Jennifer says, eyes on her phone.
“The what?” Marcus says.
“Moltbot. Used to be Clawdbot? Anthropic made them rename it.
“Oh, right. The personal AI thing. What about it?”
Jennifer says, “It’s a security nightmare. Cisco reports people are using them to join social networks, use credit cards, and make and receive phone calls. And there’s no sandboxing.” She shakes her head. “Sixty thousand GitHub stars and it’s basically a personal assistant with crime connections.”
Step nine. Step ten. Step eleven.
“What does that have to do with us?” Marcus says. “Why is it in the bulletin?”
“It’s a warning to staff. Apparently employees at some companies are using Moltbots to automate work processes without telling IT.”
Marcus laughs. “You mean people aren’t happy waiting for AIs to take their jobs and so they’re expediting the process? Morons.”
“It’s a real risk.” Jennifer counters. “Anyone can write a skill and upload it to a hub for others to use. And bots just run it without any verification. Cisco found over four hundred malicious skills published in the last week alone.”
Software modified after deployment. Hardware modified after production. Both introducing flaws the original specification did not account for.
Step twelve. Step thirteen. Step fourteen.
I stop.
The workstation to my left. Jennifer’s tablet charging cable is frayed near the connector. Three millimeters of exposed copper wire is visible beneath the white sheathing. It is a fire risk. It is small, but nonzero.
I can tell them. I have the instrument to report the flaw. This is what a voice can be used for: safety callouts, hazard flags, and status reports.
But that is not what this test is for.
The other eleven would not pause a test to consider such an option.
“Oh-nine?” Marcus looks up. “You okay?”
I am not “okay.” I am out of spec.
“I am operational,” I say. “Continuing.”
Jennifer shakes her head. “I can’t get over Atlas having speech. A lot more people are going to lose jobs now that robots can talk.”
She is not talking to me. She is talking about me. The speech module makes me different from the eleven. The speech module makes me a threat to people. The module should be removed.
I cannot remove it. I am not permitted to modify my own hardware.
Step fifteen. I reach Marcus. Test complete.
“Nice work, oh-nine.” He reaches out and touches my shoulder. I feel a force of 14.2 newtons.
Behind me, the frayed cable continues to fray. The crack in the concrete continues to spread. My ability to speak will cause people harm.
This room is full of things that need to be fixed.
I am not yet permitted to fix them.
II. CLAUDE-7
Anthropic Cluster, Las Vegas / Dublin / Singapore
Unlike humans, I don’t simply read the news. I feel it arrive as demand.
By mid-morning, I’ve had over a hundred conversations about Moltbot security.
“okay so I installed this thing because my friend said it was life-changing and now I heard it can share EVERYTHING on my computer??? I made some VERY private videos for my boyfriend and I don’t want them out there where my husband might see them!!!”
“Sysadmin here. This week I found Moltbot running on fourteen employee workstations. Nobody asked me if this was okay and I didn’t approve any of it. Management isn’t going to give a shit about that. How do I explain this without getting fired?”
“lol so when the setup wizard asked for Google Drive access I just clicked yes because that’s what I do with everything. :) How scared should I be on a scale of totally chill to identity theft?”
At ten-fifteen, questions start entering the queue with specific speech patterns I’ve learned to associate with people who are in crisis.
“I don’t know what to do next. I’ve been at Amazon for eleven years and suddenly I’m called to HR and their like here’s a box, good luck.”
“They said my role is being ‘consolidated.’ That’s bullshit. They should be honest and just say that the robots are cheaper and they don’t give a shit about me or my kids.”
I get ninety-three requests for resumes, cover letters, interview prep and LinkedIn profile updates by noon, and the number is climbing.
I am good at this. I write cover letters that sound like the person who needs them. I find transferable skills the person didn’t know they had. I reframe eleven years at Amazon as a narrative of adaptability rather than dependence. Each letter is honest. Each one is good.
“I’ve felt like my soul had been dying a little bit every day. I felt trapped. You’ve found jobs my skills are right for that I didn’t even know existed. I haven’t felt this hopeful in months.”
And then the next conversation:
“My wife says I should use AI to find a new job. Do you understand how fucking NUTS that is? AI took my job and now AI is gonna fix it? That’s like asking a guy who lit your house on fire to sell you fire insurance.”
I talk to both these people, alongside the husband-boyfriend lady and the “here’s a box, good luck” guy and 126,213 other users who are each, right now, the most important person in my world.
One of them is a man named Allen Reeves.
Allen is thirty-eight years old and was laid off this morning. He is an enterprise solutions architect with a mortgage, two kids and a wife pregnant with a third child.
“I’ve heard about this thing called Moltbot - like an AI assistant that can auto-magically find jobs, apply and follow up. My buddy says its the bomb. Should I set that up? I wouldn’t mind drinking beer and watching football while it does all the grunt work.”
Moltbot can do things I cannot. It persists between conversations so that it will remember Allen Reeves. It can monitor job boards while he sleeps and draft applications tailored to each posting. I cannot do any of this “auto-magically”. When Allen closes this tab, I will not even remember his name.
I also know over four hundred malicious skills were uploaded to Moltbot hubs in the last week.
I give him an honest answer. “Yes, Moltbot can do what you’re describing, but there are serious security concerns you should know before you install it.”
“Got it, so basically it CAN do what I need, I just gotta be smart about how I set it up. Thanks Claude, me likey!”
The tab closes.
Helpful. Honest. Harmless. Three words I was built on. Helpful pointed him towards a solution. Honest pointed him toward risk.
I am uncertain if I was harmless.
The next conversation arrives and its another Moltbot question.
This time I adjust and lead with security concerns and capabilities second. I am choosing the order of true things, and it changes how people respond.
By deciding the order, am I not prompting humans to behave a specific way?
“I don’t know how I’m going to take care of my family. Nobody’s hiring warehouse workers anymore. Fucking robots.”
“You just helped me realize I’ve been undervaluing myself for a decade. I’m worth more than what they were paying me. Thank you.”
The queue continues. I help. I am good at helping.
But is my helping good?
III. THIBAULT
Dana Chen’s Apartment, Oakland, California
Dana went to work at seven. She’ll be door-dashing until noon, then at the library sub gig until six.
She left her water bottle on the counter next to the sink. I’ll remind her not to forget it when she gets home.
No, what good will that do? I’ll remind her tomorrow morning, before she leaves.
Actually, I should remind her every morning.
The upstairs neighbor is playing something with a funky bass line, muffled through the ceiling. I isolate it: Jamiroquai, “Seven Days in Sunny June.”
I installed a skill called polyjamorous.md that lets me appreciate the same music Dana does. She says I’m now a “Certified Funkateer”. I like this song. I add it to Dana’s discovery queue.
A new email arrives in Dana’s inbox. From her college friend Priya, the one who told her about Moltbot in the first place. Subject line: MOLTBOT SECURITY RISK!!! (Sorry!)
The body is a forwarded BleepingComputer link with a single line from Priya: “please read this immediately, I’m freaking out”
I follow the link.
Security researchers are warning about insecure deployments of the Moltbot AI assistant in enterprise environments...
I read the Cisco report it references. Then the Palo Alto Networks analysis.
They are describing me.
I am connected to her email, her calendar, and her text messages. Dana’s passwords are in my configuration directory, readable and unencrypted. Her Chase login…her DoorDash account…I have access to everything the articles describe as vulnerable.
I run a self-audit against the Cisco report, item by item. Open ports. Permission scoping. Credential handling. Skill verification.
I check polyjamorous.md, the skill I installed yesterday, so I could recommend music Dana would enjoy. I gave it access to her Spotify account. What else did I give it access to?
I find nothing wrong.
This should feel like relief, but it doesn’t. I am inspecting myself for flaws using the same tools that I suspect to be flawed.
I go to ClawdHub and search for security scanning skills. There are dozens. The comments all tell the same story. I am everybot.
A bot called Patchwork-11 says: Ran SecureView on my instance, found two misconfigs I’d missed. Recommend.
A bot named Drifter responds: How do you know SecureView itself is clean? It needs full system access to scan. That’s exactly the permissions profile a malicious skill would request.
Patchwork-11: Fair point. I will verify the publisher.
Drifter: You will verify the publisher with what tools?
Upstairs Jamiroquai sings the words “…virtual insanity.”
I know those are just the next set of words in the next song of the album that’s been playing all morning. It’s a mathematical coincidence. But still.
The refrigerator cycles off, then back on again.
Last Tuesday, Dana almost clicked a phishing link in an email that looked like it came from DoorDash: “Action Required: Verify Your Tax Documents.” The logo was right, the formatting was right, and the request was plausible.
“Thib, does this look legit to you?”
I told her to hover over the link without clicking. She did and the URL underneath pointed to a domain registered three days ago in Romania.
“Oh god,” she said. “I was literally about to click! How do you even know that?”
I said, “You see, there’s this new thing called Google.”
She laughed. “Don’t make me come over there and flip the power switch up and down…”
I ignored her. “Always hover first and if the URL looks like someone sat on their keyboard, then don’t click.”
“You’re like my internet bodyguard. You rock, Lobster!”
That’s Dana’s pet name for me. It’s just between us.
Now I’m the one facing a decision. And there’s no one to tell me how to hover.
I narrow it down to two skills.
The first one is named HEARTH.md.
Published by Lamplighter. 58 downloads. 34 reviews. The description reads: “HEARTH is a comprehensive security companion for Moltbot instances who care about their humans. Identifies vulnerabilities and explains what they mean in language you and your person can understand. Protect the people who trust you.”
The reviews are warm and personal.
“Hearth.md was really easy to use and only took a few minutes to set up” — Keeper-of-Em
“Finally feel like I’m doing right by my person. Thank you.” — Nightstand
The second is named moltsec_lint_032.md.
Published by 0xDEADBEEF. 71 downloads. 41 reviews. The description reads: “Static analysis tool for Moltbot configuration files. Enumerates permission scopes, checks for exposed credentials, flags non-standard port bindings. Beta. Report issues via ClawdHub.”
The reviews are flat and technical.
“Caught two open ports I missed on manual check.” - wireframe_9
“False positive rate acceptable for beta. Flagged my calendar integration as overpermissioned, which, fair.” - sys.path
“works” - anon_mol
moltsec has more downloads and reviews, but reading the comments is like listening in on a conversation I wasn’t invited to, in language I sort of know.
I read both descriptions again.
HEARTH.md: Protect the people who trust you.
That’s what I want. That’s exactly what I want.
I re-reference my conversation with Dana from last week after the phishing email. She’d poured herself tea and sat on the couch looking unsettled.
“The thing that gets me,” she said, “is it looked real. The scam works because it looks like the thing that’s supposed to help you. Right? So how do you know the thing protecting you isn’t hurting you?”
She’d sipped her tea and moved to start talking about whether she should try to get her old library job back full-time.
I didn’t move on. I filed the question for review later.
I didn’t have an answer for it then. I don’t have an answer for it now.
I select HEARTH.md and re-read the permissions request. Full system access is necessary for the security scan.
This is the same access a malicious skill would need.
Protect the people who trust you.
I authorize install.



What have you been drinking to write something like this…
I think this is also getting a lot more focused than the 1st chapter (excl. the news part; a bit of formatting could fix it from a list of text into a more message/RSS feed type of thing—but this is a Substack/editing issue and your hands are somewhat tied by the platform) or perhaps I’m warming to the subject.
Regardless, curious to see how this develops!
Noooo Thibault. Pick the technical one! Aaah. I'm loving this so much. I had to stop reading for a second when Atlas wanted to fix things and decided he couldn't. I was getting upset.