4 ms·
What’s the security situation around OpenClaw today? It was just a week or two ago that there was a ton of concern around its security given how much access you
by kylegalbraith 8mo ago
What’s the security situation around OpenClaw today? It was just a week or two ago that there was a ton of concern around its security given how much access you give it.
- bowsamic 8mo agoMany companies have totally banned it. For example at Qt it is banned on all company devices and networks
- ricardobayes 8mo agoCan only reasonably be described as "shitshow".
- kolja005 8mo agoMy company has the github page for it blocked. They block lots of AI-related things but that's the only one I've seen where they straight up blocked viewing the source code for it at work.
- mcintyre1994 8mo agoI don’t think there’s any solution to what SimonW calls the lethal trifecta with it, so I’d say that’s still pretty impossible. I saw on The Verve that they partnered with the company that repeatedly disclosed security vulnerabilities to try to make skills more secure though which is interesting: https://openclaw.ai/blog/virustotal-partnership https://openclaw.ai/blog/virustotal-partnership I’m guessing most of that malware was really obvious, people just weren’t looking, so it’s probably found a lot. But I also suspect it’s essentially impossible to actually reliably find malware in LLM skills by using an LLM.
- madeofpalk 8mo agoHonestly, 'malware' is just the beginning it's combining prompt injection with access to sensitive systems and write access to 'the internet' is the part that scares me about this. I never want to be one wayward email away from an AI tool dumping my company's entire slack history into a public github issue.
- veganmosfet 8mo agoRegarding prompt injection: it's possible to reduce the risk dramatically by: 1. Using opus4.6 or gpt5.2 (frontier models, better safety). These models are paranoid. 2. Restrict downstream tool usage and permissions for each agentic use case (programmatically, not as LLM instructions). 3. Avoid adding untrusted content in "user" or "system" channels - only use "tool". Adding tags like "Warning: Untrusted content" can help a bit, but remember command injection techniques ;-) 4. Harden the system according to state of the art security. 5. Test with red teaming mindset.
- habinero 8mo ago> Adding tags like "Warning: Untrusted content" can help It cannot. This is the security equivalent of telling it to not make mistakes. > Restrict downstream tool usage and permissions for each agentic use case Reasonable, but you have to actually do this and not screw it up. > Harden the system according to state of the art security "Draw the rest of the owl" You're better off treating the system as fundamentally unsecurable, because it is. The only real solution is to never give it untrusted data or access to anything you care about. Which yes, makes it pretty useless.
- veganmosfet 8mo agoAgree for a general AI assistant, which has the same permissions and access as the assisted human => Disaster. I experimented with OpenClaw and it has a lot of issues. The best: prompt injection attacks are "out of scope" from the security policy == user's problem. However, I found the latest models to have much better safety and instruction following capabilities. Combined with other security best practices, this lowers the risk.
- habinero 8mo ago> I found the latest models to have much better safety and instruction following capabilities. Combined with other security best practices, this lowers the risk. It does not. Security theater like that only makes you feel safer and therefore complacent. As the old saying goes, "Don't worry, men! They can't possibly hit us from this dist--" If you wanna yolo, it's fine. Accept that it's insecure and unsecurable and yolo from there.
- veganmosfet 8mo agoIt's still bad, even if they fixed some low hanging fruits. Main issue: prompt injection when using the LLM "user" channel with untrusted content (even with countermeasures and frontier model) combined with insecure config / plugins / skills... I experimented with it: https://veganmosfet.github.io/2026/02/02/openclaw_mail_rce.html https://veganmosfet.github.io/2026/02/02/openclaw_mail_rce.h...
- geoandgeox 8mo ago[dead]