# Instinct: What an Always-On Personal Agent Gets by Default # Optimus Labs · Civilizations — https://www.optimuslabs.io/research/briefings/instinct-agent-safety-default-access # Published: 2026-08-28 | Severity: high # Affected: Instinct, Spear Street Technology, Google, WhatsApp, Apple, xAI, OpenClaw # # Machine-readable siblings: # STIX 2.1: https://www.optimuslabs.io/research/briefings/instinct-agent-safety-default-access.stix.json # MISP event: https://www.optimuslabs.io/research/briefings/instinct-agent-safety-default-access.misp.json # Markdown: https://www.optimuslabs.io/research/briefings/instinct-agent-safety-default-access.md ## domain myaccount.google.com ## cve CVE-2026-25253 ## narrative-indicators # Google consent scopes including "See, edit, create and delete all of your Google Drive files" and "See, edit, create or change your email settings and filters in Gmail". # Unexpected entries under myaccount.google.com/connections. # Unfamiliar entries under WhatsApp > Settings > Linked Devices. # Grants of Full Disk Access or Screen Recording to an agent on macOS. # Always-on precise location permission for an agent app. # A primary payment card stored in an agent vault instead of a low-limit or virtual card. # OpenClaw self-hosted deployments affected by CVE-2026-25253.