picoclaw is vulnerable to OS command injection via the ExecTool component (CVE-2026-36045) | HOL Guard CVE